Cloud infrastructure provider
Compute, managed relational database, object storage, and edge network for the control plane. Region pinned to Germany. SOC 2 Type II and ISO 27001 certified. Specific vendor disclosed by name in the customer DPA.
Data residency, encryption posture, audit posture, subprocessor registry, and incident response, written for the procurement team that reads them. No marketing softeners.
Customer data, scan findings, and judge rationales live in EU infrastructure (Germany region).
Nightly off-site backups are age-encrypted at rest with keys held by a separate operator role.
Append-only audit log retention is tenant-configurable up to ten years for GRC review windows.
With the on-prem gateway agent, prompts and tool arguments never leave the customer network. Only allow / block decisions and redacted finding metadata flow upstream.
Every subprocessor is contracted under EU Standard Contractual Clauses where international transfer applies. Material changes are notified at least 30 days in advance per the Data Processing Addendum.
Compute, managed relational database, object storage, and edge network for the control plane. Region pinned to Germany. SOC 2 Type II and ISO 27001 certified. Specific vendor disclosed by name in the customer DPA.
DDoS mitigation, web application firewall, TLS 1.3 termination, and CDN for the public surface. Customer traffic terminates at the EU edge before reaching origin.
Three independent LLM providers (Anthropic, OpenAI, Google) score adversarial scan responses, plus a meta-judge that resolves disagreement. Only the adversarial prompt and the model response cross the boundary; customer secrets stay encrypted under authenticated public-key cryptography.
Subscription billing handled by certified PCI DSS Level 1 processors. We do not store cardholder data. All customers are billed in EUR.
Magic-link sign-in messages, scan reports, and operator notifications. Region pinned to the European Union; SPF, DKIM, and DMARC enforced.
Privacy-respecting first-party analytics. No cookies, no fingerprinting, no third-party advertising tags. Aggregate page-view counts only.
Subprocessor names are disclosed by vendor in the customer DPA, alongside data categories processed, region, and last review date. We treat vendor identities as commercially sensitive on the public surface but never withhold them from a paying or prospective customer who requests the DPA.
Certified today. ISO/IEC 27001 information security management system, audited and active. Every finding also ships with control identifiers from OWASP LLM Top 10, OWASP Agentic Top 10, NIST AI 600-1 plus NIST 800-218A, MITRE ATLAS, EU AI Act high-risk provider obligations, and ISO/IEC 42001 Annex A.
Planned. SOC 2 Type II is planned. We will publish the attestation once the audit is complete; it is then available to customers under NDA on request.
Working toward. An ISO/IEC 42001 audit. We will publish each attestation as it is signed; we do not claim certifications we have not yet earned.
Security researchers and customers reach us through a single intake. We acknowledge, we assess, we patch, we publish, on a published schedule.
Reports come in through the machine-readable contact at /.well-known/security.txt (RFC 9116) and via [email protected] . PGP key available at /.well-known/pgp-key.txt.
Critical under 24 hours, high under 7 days, medium under 30 days, low at the next release. Severity is set against CVSS 4.0 and the OWASP Risk Rating model.
90-day coordinated disclosure. We will not bring legal action against researchers who follow the policy and operate in good faith.
Every subprocessor is contracted under Standard Contractual Clauses or an adequacy decision where international transfer applies. Material changes are notified at least 30 days in advance per the Data Processing Addendum.
Vendor names are disclosed by name in the customer DPA alongside data categories, region, and last-review date. Vendor identities are treated as commercially sensitive on the public surface but never withheld from a paying or prospective customer who requests the DPA.
Tick-by-tick alignment with enterprise AI procurement questionnaires (SIG, CAIQ, custom AI risk addenda).
GDPR Article 28 Data Processing Addendum published at /legal/dpa. Counter-signature available within five business days.
Public table above; named-vendor list shared under DPA for paying or prospective customers.
Full architecture deep-dive at /security covering tenant isolation, encryption, audit log, and incident response.
90-day coordinated disclosure window, RFC 9116 security.txt, severity SLA (critical <24h triage, high <7d, medium <30d).
Primary region: EU (Germany). Backups encrypted at rest. Per-tenant residency overrides available under enterprise contract.
Self-hosted gateway mode: zero prompt bytes leave the customer VPC. Hosted mode: prompts redacted at the wire before judge submission; raw prompts not retained.
Per-tenant retention from one day to ten years. Append-only audit log mirrored to a tamper-evident audit channel.
Findings ship pre-mapped to EU AI Act high-risk provider obligations (Art. 9, 10, 12, 14, 15, 17, 72). PDF + JSON evidence export.
DPA, security architecture summary, subprocessor list, and a sample audit-evidence export in one PDF.