Qtrac is now Frontlion. Learn more →

Platform

Security and compliance your review team can verify

Frontlion is the in-person service platform for banks, government agencies, health systems, and retailers. It protects customer information and supports regulatory requirements, with enterprise security enforced by default in every deployment.

Enforced by Default

What ships in every deployment

Enterprise security designed for service operations: part of every interaction, not a feature added after deployment.

SSO
SAML and OIDC, enforced tenant-wide
AES-256
at rest, with TLS 1.2+ in transit
Every action
audit-logged with actor and timestamp
Masked
PII hidden outside need-to-know roles

Platform control posture, inspectable during your security review.

The Controls

Six controls, on by default

Single sign-on

SAML and OIDC federation: Okta, Entra ID, Ping.

In practice
Your identity provider owns sign-in and offboarding. Deactivate someone once, and access ends everywhere, kiosks included.

Role-based access

Least-privilege roles for associates, supervisors, and admins.

In practice
An associate sees today's queue, not the network. Supervisors see their locations, and every scope change is logged like everything else.

Encryption

TLS 1.2+ in transit, AES-256 at rest.

In practice
Encryption is not a setting your team has to remember. It is on for every deployment, with keys managed in the platform's Azure environment.

PII redaction

Customer data masked outside need-to-know roles.

In practice
The visit record carries what service needs, nothing more. A mobile number exists to send a notification, not to build a profile. Roles outside need-to-know see masked fields.

Data retention

Retention windows set by policy, enforced automatically.

In practice
Set the window once per data class and expiry runs on its own. No cleanup projects, no forgotten exports.

Audit export

Every action logged, exportable on demand.

In practice
Who did what, when, and from where. Examiners and your second line get a complete export in minutes.

In the Moment

Security your customers never notice

Maria joins the line from her phone; her associate sees just enough to serve her well. Details travel encrypted, appear only to the roles that need them, and expire on schedule.

Customer waiting comfortably in a branch lounge, joining the queue from her phone while the software works quietly around her

Next up

Sam C. Small business

Loan consultation

Waiting 6 min

The customer's side, live product animation

In the Product

Inspect every control in the product

Three of the controls above, shown as they run. What you evaluate is what deploys.

Every action, attributable

Actor, action, timestamp on every event. Examiners get a complete export in minutes.

Live product animation

Compliance posture, stated plainly

SOC 2 Type II, available under NDA HIPAA BAA-ready GLBA and SOX supported WCAG 2.1 AA Annual penetration testing Cloud-native on Microsoft Azure

Current documentation for each item is shared during review, under NDA where required.

Compliance Without Compromise

Security should accelerate deployment, not slow it down

The review kit ships the day you ask. Your security team starts with answers, not a questionnaire chase.

The security review kit

  • Architecture overview
  • Data processing agreement
  • Penetration test summary
  • SOC 2 report, under NDA

Shared under NDA on request.

Next step

Bring your security questionnaire

We will bring the documentation and the product, with the answers your review needs in writing.