Security.
Final Frame holds unreleased masters, deal terms and the records around them. These are the controls that protect them, from who can reach a file to how the code that serves it is built.
Separation between organisations
ControlWhat happens
Own storageEach organisation's media sits in a storage bucket of its own
Own keysEach bucket is encrypted under the organisation's own key in Cloud KMS, rotated every 90 days
Own identityEach organisation's storage is reached through a service identity of its own
Row-level isolationPostgres row-level security on every table that holds organisation data
Default denyA query with no organisation named returns nothing
Tested every changeAn isolation test suite runs in CI against the same database roles as live
Who gets in
ControlWhat happens
Two-factor sign-inSign-in through WorkOS supports an authenticator app as the second factor
Single sign-onYour own Okta, Entra ID or Google Workspace, once your domain is verified
Invitation onlyPeople join by invitation; a membership is the only thing that grants access
PermissionsEvery request is checked on the server against fine-grained permissions, denied by default
SessionsA session ends after 30 minutes idle and after 12 hours in any case
Scoped keysAPI keys carry only the permissions chosen for them, show once and revoke in a click
Content in motion and at rest
ControlWhat happens
Signed linksEvery upload and download uses a link for one file, valid 15 minutes by default and an hour at most
Direct to storageMedia moves straight between your machine and storage, never through the API
Links stay privateA signed link is handled as a credential and never written to a log
In transitTLS 1.2 or higher, with HSTS on every response
At restAES-256 on every file and every database record
Virus scanningAttachments arriving in a project inbox are scanned with ClamAV before anyone can open them
The record
ControlWhat happens
Audit trailUploads, receipts, removals, status changes, deliveries and download links, each with who acted
Append-onlyEntries are added and never changed or removed for the life of your organisation
Keys and agentsEvery action by an API key or an assistant names the credential that took it
Support accessA support session inside your organisation lasts 30 minutes and is written to your audit trail
Platform logsChanges to storage and every use of keys and secrets are logged and kept for 365 days
How the software is built
ControlWhat happens
Static analysisCodeQL security queries on every change and again every week
Secret scanninggitleaks over the code's whole history on every change
DependenciesA high or critical advisory in shipped code fails the build; updates are proposed weekly
Bill of materialsA CycloneDX software bill of materials with every build
Every change checkedType checks, lint, tests and the isolation suite run in CI on every change
Where it lives and how it recovers
ControlWhat happens
Data residencyYour content and records are stored in Google Cloud's London region
BackupsThe database is backed up daily
Point-in-time recoveryThe database can be restored to any moment in the last seven days
DeletionDeleting a file removes it and its proxies; a recoverable copy is kept for seven days, then deleted
For a security review, ask for the detail behind each control when you sign up.