Skip to content
Trust centre

Everything your review board will ask for, already written.

Certifications, architecture, sub-processors, incident history and the standard questionnaire responses. Most security reviews close in days because the answers are not being written for the first time.

Current
SOC 2 Type II
Report available under NDA
Certified
ISO/IEC 27001
Information security management
Certified
ISO/IEC 42001
AI management system
Compliant
GDPR
EU representative appointed, SCCs in place
Available
HIPAA
BAA available for healthcare deployments
Ready
EU AI Act
Annex IV documentation generated per system
Security posture

How the platform is built and defended.

Deployment modelDefault is your tenant, your cloud account, your region. Managed hosting is opt-in, never assumed.
EncryptionTLS 1.3 in transit, AES-256 at rest, customer-managed keys supported on all persistent stores.
Identity and accessSSO via SAML or OIDC, SCIM provisioning, role-based access, and just-in-time elevation for support staff.
Tenant isolationLogical isolation by default, dedicated infrastructure available. No shared vector indexes across clients.
Model providersZero-retention agreements with every hosted provider. Self-hosted and air-gapped options for restricted data.
TestingIndependent penetration test annually, continuous dependency scanning, and internal red-teaming each release.
Availability99.9% contractual SLO for managed deployments, multi-zone by default, documented RTO and RPO.
PersonnelBackground-checked staff, annual security and AI-ethics training, least-privilege access reviewed quarterly.
Sub-processors

Who else touches the data, and where.

In a client-tenant deployment this list is usually empty: the platform runs entirely inside your boundary. Where our managed service is used, these are the processors involved. Clients are notified 30 days before any addition.

Amazon Web ServicesManaged platform hosting and storageClient-selected
Microsoft AzureManaged platform hosting, Azure OpenAI inferenceClient-selected
Google CloudManaged platform hosting and inferenceClient-selected
Model providersInference under zero-retention terms, per routing policyPolicy-constrained
Observability vendorAggregated operational telemetry, no customer contentEU and US
Incidents

We publish these whether or not you ask.

Any incident affecting confidentiality, integrity or availability is disclosed to affected clients within 24 hours of confirmation, with a full write-up inside five business days.

Report a vulnerability
Aug 2026
No reportable incidents
Quarterly attestation published to clients on 1 September.
May 2026
No reportable incidents
Quarterly attestation published to clients on 1 June.
Feb 2026
Dependency vulnerability, no exposure
Third-party library advisory patched within 18 hours. No customer data affected. Write-up circulated.