Where our security stands today.
Diligence starts with status, so here's ours in plain words: the frameworks our controls are aligned with, the policies behind them, and what every client gets as standard. We update it as things change.
SOC 2 / ISO 27001
Aligned with the SOC 2 Trust Services Criteria and ISO 27001, with controls already live. We're entering the SOC 2 Type II observation period.
36 security policies
Covering personnel security, access management, secure development, data classification, encryption, incident response and vendor management.
Secure by design
Our safeguards aren't configured per project or sold as extras. Every client gets all of them as standard, from the first day of the engagement.
Six controls built into the platform.
These controls live in the architecture, not just in policy. That's deliberate: policies depend on people remembering them, but the architecture doesn't forget.
Azure-native infrastructure
The core infrastructure runs on Azure-managed services: AKS compute that scales with demand, Blob storage and managed disks, and networking through Application Gateway with WAF, VPN Gateway and private endpoints.
Tenant isolation
Each client is its own security boundary, logically separated with its own data store, users, access controls and messaging namespace. Production runs as a separate tenant from dev, QA and staging, so no one working in a lower environment can reach production data.
Access control
Role-based access down to component and record level, with least privilege applied, and multi-factor authentication for all platform users. Production access is reviewed quarterly, and sessions time out on critical systems. Your users sign in through Stytch, with SSO configurable to your identity setup.
Change governance
Nothing reaches production without automated tests and mandatory peer review, and separation of duties means engineers can't deploy their own changes. Deploys use rolling replacement, for zero downtime.
Full audit trails
Every tenant operation is logged immutably: data operations, access changes, API key events and service promotions, down to who changed which field. Components and records are versioned, with full change history and rollback.
Model governance
Multi-model by design, with failover between providers. Low-confidence outputs go to a person instead of failing silently, and your team reviews and corrects them. Reasoning traces are logged, drift triggers review, and autonomy is set per use case, based on the stakes.
Security is also who touches the work.
Architecture covers the systems. These processes cover the people around them, and they apply to everyone.

Background checks and offboarding
Everyone is background-verified before getting system access, including staff from our staffing providers. When someone leaves or changes role, access to all critical systems is revoked within three business days.

Third-party and vendor risk
Staffing providers pass a security risk assessment under our vendor management policy, work under master services agreements, and are contractually bound to our confidentiality and data protection terms.

Training and rules for AI tools
Everyone completes security awareness training before getting access to customer or sensitive information. They also sign our acceptable use policy, which sets rules for AI tools as well as systems and customer data.
Answers to your diligence questions.
The specifics a security review usually asks for. If you need more detail, the full documentation is available on request.
Client data is hosted on Microsoft Azure, in a region set at the start of the engagement to meet your requirements. Transactional data sits in MongoDB, files in Azure Blob Storage, caching in Azure Redis and search in Elasticsearch.
Microsoft Azure (infrastructure), Stytch (authentication), StreamNative (messaging) and AI model providers OpenAI, Anthropic and Google, via their own endpoints, Azure OpenAI or Google Vertex AI. Every option keeps your data out of model training by agreement.
Data is encrypted at rest with AES-256, using infrastructure-managed keys, and in transit with TLS 1.2 or higher. Secrets are never written to disk: they're held in Azure Key Vault, partitioned per tenant and rotated automatically.
Retention rules are set per document class to match your compliance requirements, and deletion within your isolated environment is permanent. On exit, we return your data, schemas and configurations, then scrub and decommission the environment.
Storage runs on zone-redundant managed disks, and files and records are replicated across geographically distant Azure regions. Restorations are governed by support agreements with defined response times.
Microsoft Defender for Cloud provides continuous security posture assessment, threat detection and vulnerability scanning, with remediation workflows. Code and dependencies are scanned before every build.
Azure Monitor and Defender for Cloud watch network, application and cloud boundary continuously. Incidents are graded Low to Critical, and High and Critical go straight to our Information Security Officer. Notification windows are set in your contract.