Trust Center
SOC 2 Type II certified
We ask customers to connect us to their most sensitive AI activity — prompts, documents, audit trails, cloud accounts. That only works if how we handle it is verifiable rather than asserted. Our controls for security, availability and confidentiality have been independently audited over an observation period, which is what the Type II report covers.
The full report is shared with customers and prospects under NDA. Security questionnaires, DPAs and penetration-test summaries are available through the same route.
SOC 2 Type II
Independently audited over an observation period, not a point in time.
Encrypted throughout
TLS 1.2+ in transit, AES-256 at rest, scoped and redacted credentials.
Never trained on
Your prompts and telemetry are never used to train any model.
You pick the boundary
SaaS, hybrid, self-hosted or fully air-gapped with local models.
Data boundaries
Where your data actually lives
The honest answer depends on which deployment you choose, so here is the whole matrix rather than a single reassuring sentence. "Content" means prompts, responses and documents. "Metadata" means findings, scores, counts and entity names.
| Deployment | Prompt & document content | Findings & metadata | Who operates it |
|---|---|---|---|
| Cloud SaaS | Processed and stored by SAF3AI in your chosen region | Processed and stored by SAF3AI | SAF3AI operates the infrastructure |
| Hybrid | Never leaves your network | Synced to the SAF3AI console | You operate the collector, we operate the console |
| Self-hosted | Never leaves your network | Never leaves your network | You operate everything |
| Air-gapped | Never leaves your network | Never leaves your network | You operate everything, with no outbound connectivity |
Controls
The answers to your questionnaire
Grouped the way security reviews are, so you can find the section you are being asked about. If something you need is not here, ask and we will answer directly.
Data protection
- Encryption in transit
- TLS 1.2 or higher on every external connection, including all connector traffic and the API.
- Encryption at rest
- AES-256 for all stored data, including prompt content, telemetry and the graph.
- Credential handling
- Connector credentials are encrypted at rest, scoped to a single tenant, and redacted everywhere they would otherwise surface in the product, logs or support tooling.
- Key management
- Managed keys with scheduled rotation. Self-hosted deployments use your own key management.
Tenancy and access
- Tenant isolation
- Every record carries an organisation identifier enforced at the data layer, not only in application code. Cross-tenant reads are structurally prevented rather than filtered.
- Authentication
- SSO via SAML and OIDC, with Okta and Microsoft Entra ID supported directly. MFA is enforced by your identity provider.
- Authorisation
- Role-based access control with custom roles, so an analyst, an auditor and an administrator see different things.
- Internal access
- Least-privilege access for SAF3AI staff, granted for a defined purpose and duration, and logged. Customer content is not accessed without an approved support reason.
AI-specific commitments
- Do you train models on our data?
- No. Customer prompts, responses and telemetry are never used to train or fine-tune any model, ours or a third party's.
- Where does AI analysis run?
- In the deployment you chose. Self-hosted and air-gapped installations run local models with no outbound calls to any model provider.
- What does the investigation agent do?
- It reads incident evidence and writes an assessment. It is read-only and cannot take action. Response actions are separate, explicitly invoked, and irreversible ones always require human confirmation.
- Can we audit AI decisions?
- Yes. Every severity score is explainable arithmetic, every agent verdict cites the evidence it used, and every automated action is recorded in the audit log with its reversal path.
Resilience and operations
- Availability
- Multi-zone deployment with automated failover for the managed service. Status and incident history are available to customers.
- Backups
- Encrypted automated backups with tested restore procedures.
- Vulnerability management
- Continuous dependency scanning, static analysis in CI, and remediation targets scaled to severity.
- Penetration testing
- Independent third-party testing conducted on a regular cadence. Summary reports are available to customers under NDA.
Privacy and residency
- Data residency
- Choose the region your data is processed and stored in. Hybrid and self-hosted deployments keep prompt content entirely within your own boundary.
- Retention
- Configurable retention per data type, with deletion on expiry. You set the period; the default is not the maximum.
- GDPR
- A data processing agreement is available, covering processor obligations, subprocessor transparency and international transfer mechanisms.
- Deletion on exit
- Full deletion of customer data on termination, with written confirmation on request.
Corporate security
- Personnel
- Background checks where legally permitted, confidentiality agreements, and security training at onboarding and annually.
- Change management
- Peer-reviewed changes, automated testing, and audited deployment pipelines.
- Incident response
- A documented response plan with defined severity levels and customer notification commitments.
- Vendor management
- Subprocessors are reviewed before onboarding and listed for customers on request.
Report a vulnerability
If you have found a security issue in our platform, email us with "Security" in the subject line and it will reach our security team. We do not pursue legal action against good-faith research that respects customer data and gives us reasonable time to fix.
info@saf3ai.comAsk a security question
Procurement review, architecture deep-dive, DPA, subprocessor list or a questionnaire in your own format — send it over. A security engineer answers these, not a form.
Contact our security teamBuying through a marketplace
SAF3AI is listed on Google Cloud Marketplace and Microsoft Marketplace. Through Google Cloud Marketplace you can buy directly, billed through your Google Cloud account. Microsoft Marketplace is the former Azure Marketplace. The same security review, DPA and SOC 2 report apply whichever route you buy through.