| Identity | SAML 2.0 and OIDC against your identity provider, SCIM provisioning and deprovisioning, enforced multi-factor, permissions scoped to the object rather than the module. | SOC 2 · CC6.1 · CC6.2 |
|---|
| Encryption | TLS 1.3 in transit including dock and robot upload, AES-256 at rest across object store, database, and model artifacts. HSM-backed keys, 90-day rotation, customer-managed keys on request. | SOC 2 · CC6.7 · BYOK POLICY |
|---|
| Network | Private subnets with no public database endpoints, WAF and DDoS mitigation at the edge, egress allowlists per environment, and administrative access only through short-lived brokered sessions. | PEN TEST · 2026-02 · ANNUAL |
|---|
| Monitoring | 24/7 security operations, SIEM across platform and AI services, alerting on anomalous access and model use, third-party penetration test annually, and a paid bug bounty open year-round. | SOC 2 · CC7.2 · BOUNTY LIVE |
|---|
| Resilience | Multi-zone deployment per region, point-in-time recovery, backups restored on a quarterly test rather than a promise, and a full disaster-recovery exercise run once a year with the results shared. | RTO 4H · RPO 15MIN · DR 2026-01 |
|---|
| Personnel | Background checks before start, security training on joining and annually after, least-privilege access reviewed each quarter, and production access revoked within four hours of departure. | ACCESS REVIEW · QUARTERLY |
|---|
| Vendors | Every subprocessor is reviewed before it touches customer data, listed with the data it processes and the region it runs in, and changed only after thirty days written notice to you. | SUBPROCESSORS · NOTICE 30D |
|---|