Compliance status
We publish our compliance posture the same way we publish everything else: as it actually is.
Certifications
Section titled “Certifications”SOC 2 Type II — in progress. We are pre-certification: we do not yet hold SOC 2, ISO 27001, or other certifications, and we won’t imply otherwise. Our audit-readiness program is active — policies, control matrix, and evidence collection are underway ahead of a formal audit.
What exists today
Section titled “What exists today”- Security controls inventory — an evidence-backed inventory across access control and MFA/SSO, IAM, audit logging, encryption, backups/DR, change management and secure SDLC, vendor management, HR, and incident handling, each labeled implemented / partial / not yet.
- Written security policies — acceptable use, access control, data classification, change management, vendor management, BC/DR, risk management, encryption and key management, retention and disposal, and incident response.
- Incident response runbook — roles, severities, containment, communications, and post-mortem process.
- Product security capabilities — RBAC-aware retrieval, PII scrubbing, tenant isolation, and hash-chained audit trails are built capabilities (gated to Enterprise where noted). They are not certified and not yet attested by an external auditor — we describe them as built, never as certified.
For your vendor review
Section titled “For your vendor review”Email [email protected] and we’ll walk your reviewers through exactly where the audit-readiness program stands and share what’s shareable at that point. Our architecture answers most reviews’ biggest questions structurally — start with How your data is handled and Usage data & telemetry.
Data protection
Section titled “Data protection”- Breach notification: 72-hour commitment, aligned with GDPR Article 33 timelines.
- Sub-processor changes: advance notice before new sub-processors handle customer data.
- Model inference is between you and your model provider — your existing DPA with that provider governs it, at every plan level.