Skip to content

Compliance status

We publish our compliance posture the same way we publish everything else: as it actually is.

SOC 2 Type II — in progress. We are pre-certification: we do not yet hold SOC 2, ISO 27001, or other certifications, and we won’t imply otherwise. Our audit-readiness program is active — policies, control matrix, and evidence collection are underway ahead of a formal audit.

  • Security controls inventory — an evidence-backed inventory across access control and MFA/SSO, IAM, audit logging, encryption, backups/DR, change management and secure SDLC, vendor management, HR, and incident handling, each labeled implemented / partial / not yet.
  • Written security policies — acceptable use, access control, data classification, change management, vendor management, BC/DR, risk management, encryption and key management, retention and disposal, and incident response.
  • Incident response runbook — roles, severities, containment, communications, and post-mortem process.
  • Product security capabilities — RBAC-aware retrieval, PII scrubbing, tenant isolation, and hash-chained audit trails are built capabilities (gated to Enterprise where noted). They are not certified and not yet attested by an external auditor — we describe them as built, never as certified.

Email [email protected] and we’ll walk your reviewers through exactly where the audit-readiness program stands and share what’s shareable at that point. Our architecture answers most reviews’ biggest questions structurally — start with How your data is handled and Usage data & telemetry.

  • Breach notification: 72-hour commitment, aligned with GDPR Article 33 timelines.
  • Sub-processor changes: advance notice before new sub-processors handle customer data.
  • Model inference is between you and your model provider — your existing DPA with that provider governs it, at every plan level.