SOC 2
Our access control, change management, audit logging and monitoring controls are mapped to the Trust Services Criteria. No Type I or Type II examination has been performed and no report exists.
GDPR
Data subject request tracking and export packages are built, and we act as processor for customer content under a data processing agreement. Granular consent management is not implemented, and erasure is tracked but not yet fully cascaded across derived stores.
ISO 27001
We have no ISO 27001 certificate and no certification audit is currently in progress. The underlying controls exist and are listed here; the certificate does not.
HIPAA
Some technical safeguards exist (audit chain, access control, redaction), but we do not currently offer a Business Associate Agreement. Until we do, the platform is not suitable for protected health information.
ISO 42001 (AI management)
The governance layer (agent registry, risk scoring, evaluation evidence, human oversight and the improvement loop) is mapped to AI management system criteria. Mapping is not certification.
Data residency
Regional data placement for tenant data is not offered today. Model routing can express a regional preference, which is a different and weaker guarantee, and we will not describe it as residency.
Reviewing us for a purchase?
We will answer a security questionnaire against the list above and tell you plainly which items we cannot satisfy yet. If a control you need is partial or missing, ask. We would rather scope it with you than have you find out later.
Request a security review