Trust Center
Built to be trusted with your risk data.
SecureLogic AI is a security and GRC platform — so we hold ourselves to the standards we help our customers meet. Everything you need for due diligence: our security posture, data protection, subprocessors, compliance roadmap, and legal documents.
Explore the Trust Center
Security
Multi-layer encryption, immutable audit logs, MFA/SSO, and automated cross-tenant isolation testing on every change.
Security overview →Privacy
We do not sell or share personal information. Full CCPA/CPRA, multi-state, and GDPR/UK rights with a documented data-rights process.
Privacy Policy →Responsible AI
Per-feature AI disclosure, no training on Customer Content, human oversight, and alignment to the NIST AI Risk Management Framework.
AI Policy →Compliance posture
Where we are, where we're going.
We do not currently hold independent certifications such as SOC 2 Type II or ISO 27001. We rely on the compliance posture of our infrastructure providers and the engineering controls built into the platform, and we are maturing deliberately.
Currently in place
- Multi-layer encryption (in transit, at rest, application-layer)
- Immutable security audit logs
- Multi-Factor Authentication and SSO support
- Automated security testing on every code change
- Anomaly detection and real-time operator alerting
Planned milestones
- Independent third-party penetration testing
- SOC 2 Type II attestation
- Documented Incident Response runbook
- Published Business Continuity and Disaster Recovery objectives
- Bug bounty program
Data handling & encryption
Protected at every layer.
How customer data is encrypted and handled across the platform. Your content is never used to train AI models — ours or our providers'.
| In transit | TLS encryption for all connections including database |
|---|---|
| At rest | Infrastructure-provider encryption (Render, Cloudflare R2) |
| Sensitive fields | Application-layer AES-256-GCM encryption with separate keys |
| Passwords | Argon2id hashing meeting OWASP recommendations |
| Audit logs | Database-trigger-enforced immutability |
| AI processing | No customer content used for AI model training, ours or providers' |
Full detail, including authentication and monitoring controls, is in the Security overview.
Availability & resilience
Running on resilient infrastructure — formalizing commitments next.
The platform runs on managed, redundant infrastructure today. We're transparent that formal published commitments are still on our roadmap.
In place today
- Hosted on Render with managed, backed-up Postgres databases
- Cloudflare for content delivery, DDoS protection, and object storage
- Automated database backups retained by our infrastructure providers
- Application error and performance monitoring via Sentry
Planned
Roadmap- Published uptime / status page
- Formal availability SLA for Platform and Enterprise plans
- Documented Business Continuity and Disaster Recovery objectives
Vendor security & subprocessors
The infrastructure partners behind the platform.
We keep our own supply chain small and deliberate. Each subprocessor is selected for its security posture and processes only the data needed to deliver its service.
- Render — application hosting and managed databases
- Cloudflare — content delivery, DDoS protection, object storage
- Stripe — payment processing (PCI DSS Level 1)
- Anthropic — large language model AI services
- OpenAI — speech-to-text transcription
- Sentry — application error monitoring
- Resend — transactional email delivery
The complete, current subprocessor list lives in our Privacy Policy.
Legal documents
Everything in writing.
Incident reporting & responsible disclosure
Found a vulnerability, or need to report a security concern? Email us with enough detail to reproduce the issue. Our commitments to reporters:
- Acknowledge your report within 5 business days
- Provide a substantive response within 30 days
- Credit researchers who report responsibly (with permission)