Enterprise-Grade Security
for AI Compliance
Built on SOC 2–certified infrastructure. Controls designed to align with SOC 2, GDPR, HIPAA, and NYC LL144 requirements. Your data is protected with TLS 1.2+ encryption, role-based access control, and audit logging.
Comprehensive Security Controls
Four layers of defense protecting your AI compliance data — from infrastructure to application, data, and access.
Infrastructure Security
- SOC 2–certified infrastructure providers (Vercel, Neon, Modal)
- Single-region deployment (US-East) with provider-managed redundancy
- DDoS protection and rate limiting
- Serverless deployment with provider-managed network security
- Automated security scanning in CI/CD (no third-party pentest yet)
Application Security
- Secure development lifecycle (SDLC) practices
- Automated security scanning in CI/CD pipeline
- Input validation and sanitization
- OWASP Top 10 protection
- Dependency monitoring via Dependabot and manual review
Data Protection
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Data minimization — source code never persisted, PII hashed before storage
- SHA-256 content hashing for evidence integrity
- SHA-256 hashing of candidate identifiers (NYC LL144)
- US-region deployment (self-hosted option on roadmap)
Access & Authentication
- OAuth 2.0 single sign-on via GitHub and Google
- MFA available at identity provider level (GitHub, Google)
- Role-based access control (superadmin, admin, member, viewer)
- Session management with HttpOnly cookies and automatic timeout
- Tenant isolation enforced at database query level
Compliance-Ready Architecture
Every control is mapped to applicable regulatory frameworks for audit-ready compliance.
Security & Compliance FAQs
Answers to common security questions from enterprise customers
Enterprise Security Review?
Our complete vendor security packet includes architecture diagrams, access control documentation, DPA, subprocessor list, incident response plan, and data handling policy.
View Vendor Security PacketNeed More Security Information?
Our security team is available to answer detailed questions about our infrastructure, compliance posture, and security practices.