Version 1.0 · Effective: July 1, 2026 · Last updated: July 1, 2026
Security is a foundational part of how Franshys is designed and operated. This page describes, at a general level, the practices Franshys is designed to follow to help protect the Franshys website (www.franshys.com), the Franshys application (app.franshys.com), and the data our customers entrust to us. It is provided for informational purposes and does not itself constitute a warranty or guarantee of any specific security outcome. It should be read alongside our Privacy Policy and Terms of Service.
Payments may be processed through our payment processor, which acts as Merchant of Record for qualifying transactions. Checkout is completed on our payment processor's hosted checkout page (polar.sh) rather than directly on Franshys's own servers. Franshys works to minimize its handling of sensitive payment-card information and does not collect or store full card numbers, CVV, or other sensitive card data on its own servers. Payment information is processed through our payment infrastructure/provider using payment-security controls designed to protect payment data. Card payment security across the industry is governed by standards such as PCI DSS v4.0.1; Franshys relies on its payment provider's compliance with such standards for the handling of card data during checkout.
Franshys is designed to use encryption in transit (HTTPS/TLS) across www.franshys.com and app.franshys.com so that data exchanged between your browser and our servers is protected from interception. We use industry-standard practices such as encrypting sensitive data at rest where applicable. Specific algorithms, key lengths and key-management practices are an implementation detail of the application and are not itemized on this page.
Franshys is designed to apply the principle of least privilege to internal access to customer environments and production systems, so that team members have access only to what is necessary for their role. Customer-facing accounts within the Franshys application are designed to support role-based access control (RBAC), allowing organizations to configure permissions for their own users. We use industry-standard practices such as reviewing internal access periodically.
Franshys is designed to use industry-standard practices for authentication and session management, such as password hashing (rather than storing passwords in plain text), session expiration, and secure session handling. We encourage customers to use strong, unique passwords for their Franshys accounts and to safeguard their login credentials.
Franshys is designed to monitor for known vulnerabilities in the software components it relies on and to apply security patches and updates in a timely manner as part of ongoing maintenance. We use industry-standard practices such as tracking dependency and platform updates as part of our development process.
Franshys is designed to maintain backups of customer data hosted within the Franshys application to help support recovery in the event of data loss. Backup frequency, retention periods and recovery procedures are operational details that are reviewed internally.
Franshys is designed to investigate reports of suspected security incidents affecting its systems. Where a security incident is confirmed to affect a business customer's data, Franshys intends to notify the affected customer without undue delay, consistent with our Data Processing Information page. Notification timelines may also be affected by legal or regulatory requirements applicable in a given case.
Franshys uses a limited number of third-party service providers to help operate the website and application, such as our payment provider and analytics providers. See our Subprocessors page for the list of third-party services we have identified as part of this compliance update.
If you are a security researcher and believe you have found a security vulnerability affecting Franshys, please report it to us at support@franshys.com. Please include enough detail for us to reproduce the issue (steps, affected URL or endpoint, and potential impact). We will investigate reports made in good faith and will do our best to acknowledge receipt and keep you informed of our progress. Please avoid accessing, modifying or deleting data that does not belong to you, and avoid testing that could disrupt service for other users. Franshys does not currently operate a paid bug bounty program.
Questions about this Security page, or reports of a suspected security issue, can be sent to support@franshys.com.
Business details: Franshys is operated under the trade name Astra Web Solution.