Security &
Compliance
Enterprise-grade security architecture designed for financial institution requirements: 30-day maximum media retention with a zero-storage option, SOC 2 path, and cryptographic evidence chains.
Compliance Progress
Transparent status on our certification journey. We report actual progress, not marketing claims.
SOC 2 Type II
Third-party audit of security controls, availability, and confidentiality
ISO 27001
International standard for information security management systems
GDPR Compliance
European privacy regulation with privacy-by-design architecture
Banking Security Standards
Security controls designed to meet the requirements of financial institutions.
Data Encryption
AES-256 encryption at rest, TLS 1.3 in transit
Access Controls
Role-based access with SAML SSO integration
Audit Logging
Complete activity logs with immutable timestamps
Network Security
VPC isolation, WAF protection, DDoS mitigation
Vendor Assessment
Comprehensive security questionnaires available
Data Residency
Regional deployment options for data sovereignty
Privacy-by-Design
Privacy isn't a feature we added. It's foundational to our architecture.
Zero-Storage Option
Customers who require it can have audio, images, and video analyzed in memory and discarded immediately, with nothing retained or used for training. Standard processing holds media for 30 days or less.
Detection Training Only
Customer media is used only to train our detection models and is deleted when training completes, no later than 30 days after submission. It is never used for generative purposes. Our models produce detection results and nothing else.
Minimal Data Collection
We collect only what's necessary for detection and evidence generation. No behavioral tracking, no analytics on media content.
Customer-Controlled Retention
Evidence bundles are retained based on your configured policies. You control how long evidence exists and when it's purged.
