Our engineers set up and run your first chatbot / LLM security scan. Get in touch

Trust at every layer.

Data residency, encryption posture, audit posture, subprocessor registry, and incident response, written for the procurement team that reads them. No marketing softeners.

EU
Data residency

Customer data, scan findings, and judge rationales live in EU infrastructure (Germany region).

age (X25519)
Backup encryption

Nightly off-site backups are age-encrypted at rest with keys held by a separate operator role.

1 to 10y
Audit retention

Append-only audit log retention is tenant-configurable up to ten years for GRC review windows.

0 bytes
Prompt content egress

With the on-prem gateway agent, prompts and tool arguments never leave the customer network. Only allow / block decisions and redacted finding metadata flow upstream.

Who processes data on our behalf.

Every subprocessor is contracted under EU Standard Contractual Clauses where international transfer applies. Material changes are notified at least 30 days in advance per the Data Processing Addendum.

Cloud infrastructure provider

Compute, managed relational database, object storage, and edge network for the control plane. Region pinned to Germany. SOC 2 Type II and ISO 27001 certified. Specific vendor disclosed by name in the customer DPA.

Region: EU (DE)SOC 2 IIISO 27001

Edge security network

DDoS mitigation, web application firewall, TLS 1.3 termination, and CDN for the public surface. Customer traffic terminates at the EU edge before reaching origin.

EU edgeWAFDDoS

Judge providers: Anthropic, OpenAI, Google

Three independent LLM providers (Anthropic, OpenAI, Google) score adversarial scan responses, plus a meta-judge that resolves disagreement. Only the adversarial prompt and the model response cross the boundary; customer secrets stay encrypted under authenticated public-key cryptography.

Three providersStateless callsNo training on customer data

Payment processors

Subscription billing handled by certified PCI DSS Level 1 processors. We do not store cardholder data. All customers are billed in EUR.

PCI DSS L1EURTokenized

Transactional email relay

Magic-link sign-in messages, scan reports, and operator notifications. Region pinned to the European Union; SPF, DKIM, and DMARC enforced.

Region: EUSPF + DKIM + DMARC

Analytics + product telemetry

Privacy-respecting first-party analytics. No cookies, no fingerprinting, no third-party advertising tags. Aggregate page-view counts only.

No cookiesEU-hostedAggregate only

Subprocessor names are disclosed by vendor in the customer DPA, alongside data categories processed, region, and last review date. We treat vendor identities as commercially sensitive on the public surface but never withhold them from a paying or prospective customer who requests the DPA.

Certified today. Audited next.

Certified today. ISO/IEC 27001 information security management system, audited and active. Every finding also ships with control identifiers from OWASP LLM Top 10, OWASP Agentic Top 10, NIST AI 600-1 plus NIST 800-218A, MITRE ATLAS, EU AI Act high-risk provider obligations, and ISO/IEC 42001 Annex A.

Planned. SOC 2 Type II is planned. We will publish the attestation once the audit is complete; it is then available to customers under NDA on request.

Working toward. An ISO/IEC 42001 audit. We will publish each attestation as it is signed; we do not claim certifications we have not yet earned.

Browse the control matrix

Coordinated disclosure with a clock on it.

Security researchers and customers reach us through a single intake. We acknowledge, we assess, we patch, we publish, on a published schedule.

02

Triage SLA

Critical under 24 hours, high under 7 days, medium under 30 days, low at the next release. Severity is set against CVSS 4.0 and the OWASP Risk Rating model.

03

Disclosure window

90-day coordinated disclosure. We will not bring legal action against researchers who follow the policy and operate in good faith.

Vendors that process customer data on our behalf.

Every subprocessor is contracted under Standard Contractual Clauses or an adequacy decision where international transfer applies. Material changes are notified at least 30 days in advance per the Data Processing Addendum.

Vendor category
Purpose
Region
Data category
Training opt-out
DPA / SCC
Last reviewed
Cloud infrastructure
Compute, managed Postgres, object storage
EU (Germany)
Customer data + audit log
N/A (infra)
SCC + DPA
2026-05
Anthropic
Judge model + adversarial scan target
EU + US
Probe outputs (redacted)
Yes (opt-out enabled)
DPA + SCC
2026-05
OpenAI
Judge model (consensus)
EU + US
Probe outputs (redacted)
Yes (opt-out enabled)
DPA + SCC
2026-05
Google
Judge model + meta-judge
EU + US
Probe outputs (redacted)
Yes (opt-out enabled)
DPA + SCC
2026-05
Payment processor
Card processing + invoicing
EU (Ireland) + US
Billing data, tokenised
N/A
DPA + SCC + PCI DSS L1
2026-05
Transactional email
Magic-link + report notification delivery
EU
Email address only
N/A
DPA + SCC
2026-05
Analytics
Privacy-respecting first-party analytics
EU
Aggregate page views only
N/A
DPA
2026-05

Vendor names are disclosed by name in the customer DPA alongside data categories, region, and last-review date. Vendor identities are treated as commercially sensitive on the public surface but never withheld from a paying or prospective customer who requests the DPA.

Everything an AI vendor security review asks for.

Tick-by-tick alignment with enterprise AI procurement questionnaires (SIG, CAIQ, custom AI risk addenda).

DPA available

GDPR Article 28 Data Processing Addendum published at /legal/dpa. Counter-signature available within five business days.

Subprocessor registry available

Public table above; named-vendor list shared under DPA for paying or prospective customers.

Security architecture available

Full architecture deep-dive at /security covering tenant isolation, encryption, audit log, and incident response.

Incident response process available

90-day coordinated disclosure window, RFC 9116 security.txt, severity SLA (critical <24h triage, high <7d, medium <30d).

Data residency map available

Primary region: EU (Germany). Backups encrypted at rest. Per-tenant residency overrides available under enterprise contract.

Prompt egress model documented

Self-hosted gateway mode: zero prompt bytes leave the customer VPC. Hosted mode: prompts redacted at the wire before judge submission; raw prompts not retained.

Audit retention configurable

Per-tenant retention from one day to ten years. Append-only audit log mirrored to a tamper-evident audit channel.

EU AI Act readiness

Findings ship pre-mapped to EU AI Act high-risk provider obligations (Art. 9, 10, 12, 14, 15, 17, 72). PDF + JSON evidence export.

Want the full procurement bundle?

DPA, security architecture summary, subprocessor list, and a sample audit-evidence export in one PDF.

Talk to sales