Skip to main content
SECURITY & TRUST

Enterprise-Grade Security
for AI Compliance

Built on SOC 2–certified infrastructure. Controls designed to align with SOC 2, GDPR, HIPAA, and NYC LL144 requirements. Your data is protected with TLS 1.2+ encryption, role-based access control, and audit logging.

SOC 2 Readiness In Progress
GDPR-Aligned Design
NYC LL144 Aligned
HIPAA Controls Aligned
CCPA-Aligned Design
SOC 2
Working Toward Type II
TLS 1.2+
In-Transit Encryption
AES-256
At-Rest Encryption
7 Years
Audit Log Retention

Comprehensive Security Controls

Four layers of defense protecting your AI compliance data — from infrastructure to application, data, and access.

Infrastructure Security

  • SOC 2–certified infrastructure providers (Vercel, Neon, Modal)
  • Single-region deployment (US-East) with provider-managed redundancy
  • DDoS protection and rate limiting
  • Serverless deployment with provider-managed network security
  • Automated security scanning in CI/CD (no third-party pentest yet)

Application Security

  • Secure development lifecycle (SDLC) practices
  • Automated security scanning in CI/CD pipeline
  • Input validation and sanitization
  • OWASP Top 10 protection
  • Dependency monitoring via Dependabot and manual review

Data Protection

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Data minimization — source code never persisted, PII hashed before storage
  • SHA-256 content hashing for evidence integrity
  • SHA-256 hashing of candidate identifiers (NYC LL144)
  • US-region deployment (self-hosted option on roadmap)

Access & Authentication

  • OAuth 2.0 single sign-on via GitHub and Google
  • MFA available at identity provider level (GitHub, Google)
  • Role-based access control (superadmin, admin, member, viewer)
  • Session management with HttpOnly cookies and automatic timeout
  • Tenant isolation enforced at database query level

Compliance-Ready Architecture

Every control is mapped to applicable regulatory frameworks for audit-ready compliance.

SOC 2 Type II
GDPR Art 32
HIPAA 164.312
NYC LL144
CCPA
ISO 27001
NIST AI RMF
EU AI Act
Colorado AI Act
ISO 42001

Security & Compliance FAQs

Answers to common security questions from enterprise customers

Enterprise Security Review?

Our complete vendor security packet includes architecture diagrams, access control documentation, DPA, subprocessor list, incident response plan, and data handling policy.

View Vendor Security Packet

Need More Security Information?

Our security team is available to answer detailed questions about our infrastructure, compliance posture, and security practices.