Trust Center

Built to be trusted with your risk data.

SecureLogic AI is a security and GRC platform — so we hold ourselves to the standards we help our customers meet. Everything you need for due diligence: our security posture, data protection, subprocessors, compliance roadmap, and legal documents.

Security

Multi-layer encryption, immutable audit logs, MFA/SSO, and automated cross-tenant isolation testing on every change.

Security overview

Privacy

We do not sell or share personal information. Full CCPA/CPRA, multi-state, and GDPR/UK rights with a documented data-rights process.

Privacy Policy

Responsible AI

Per-feature AI disclosure, no training on Customer Content, human oversight, and alignment to the NIST AI Risk Management Framework.

AI Policy

Compliance posture

Where we are, where we're going.

We do not currently hold independent certifications such as SOC 2 Type II or ISO 27001. We rely on the compliance posture of our infrastructure providers and the engineering controls built into the platform, and we are maturing deliberately.

Currently in place

  • Multi-layer encryption (in transit, at rest, application-layer)
  • Immutable security audit logs
  • Multi-Factor Authentication and SSO support
  • Automated security testing on every code change
  • Anomaly detection and real-time operator alerting

Planned milestones

  • Independent third-party penetration testing
  • SOC 2 Type II attestation
  • Documented Incident Response runbook
  • Published Business Continuity and Disaster Recovery objectives
  • Bug bounty program

Data handling & encryption

Protected at every layer.

How customer data is encrypted and handled across the platform. Your content is never used to train AI models — ours or our providers'.

Data protection controls by layer
In transitTLS encryption for all connections including database
At restInfrastructure-provider encryption (Render, Cloudflare R2)
Sensitive fieldsApplication-layer AES-256-GCM encryption with separate keys
PasswordsArgon2id hashing meeting OWASP recommendations
Audit logsDatabase-trigger-enforced immutability
AI processingNo customer content used for AI model training, ours or providers'

Full detail, including authentication and monitoring controls, is in the Security overview.

Availability & resilience

Running on resilient infrastructure — formalizing commitments next.

The platform runs on managed, redundant infrastructure today. We're transparent that formal published commitments are still on our roadmap.

In place today

  • Hosted on Render with managed, backed-up Postgres databases
  • Cloudflare for content delivery, DDoS protection, and object storage
  • Automated database backups retained by our infrastructure providers
  • Application error and performance monitoring via Sentry

Planned

Roadmap
  • Published uptime / status page
  • Formal availability SLA for Platform and Enterprise plans
  • Documented Business Continuity and Disaster Recovery objectives

Vendor security & subprocessors

The infrastructure partners behind the platform.

We keep our own supply chain small and deliberate. Each subprocessor is selected for its security posture and processes only the data needed to deliver its service.

  • Renderapplication hosting and managed databases
  • Cloudflarecontent delivery, DDoS protection, object storage
  • Stripepayment processing (PCI DSS Level 1)
  • Anthropiclarge language model AI services
  • OpenAIspeech-to-text transcription
  • Sentryapplication error monitoring
  • Resendtransactional email delivery

The complete, current subprocessor list lives in our Privacy Policy.

Legal documents

Everything in writing.

Incident reporting & responsible disclosure

Found a vulnerability, or need to report a security concern? Email us with enough detail to reproduce the issue. Our commitments to reporters:

  • Acknowledge your report within 5 business days
  • Provide a substantive response within 30 days
  • Credit researchers who report responsibly (with permission)
security@securelogicai.com