๐ก๏ธ Security & Compliance Trust Portal
AssurAI Security Posture
We take security seriously. Review our certifications, security practices, policies, and data handling commitments below.
SOC 2 In Progress
GDPR Compliant
HIPAA Ready
Zero Data Retention AI
99.9% Uptime SLA
๐
Certifications & Compliance
In Progress
SOC 2 Type II
Audit window: Q3 2026
Planned
ISO 27001
Target: Q1 2027
Applicable โ
HIPAA
BAA available on request
Compliant โ
GDPR
DPA available ยท EU SCCs in place
N/A
PCI DSS
No cardholder data processed
๐ Security Overview
๐
Encryption at Rest
AES-256 via Supabase / AWS
๐
Encryption in Transit
TLS 1.3 on all connections
๐
Data Residency
AWS us-east-1 (US)
๐
Uptime SLA
99.9% โ Status page available
๐
Penetration Testing
Annual โ Last: Q1 2026
๐ก๏ธ
Vulnerability Scanning
Weekly automated scans
๐จ
Incident Response
<72h notification SLA
๐ค
Access Control
MFA required ยท RBAC ยท SSO
๐พ
Data Backup
Daily backups ยท 30-day retention
๐ Policies
๐ Privacy Policy
๐ Security Policy (Summary)
๐ Acceptable Use Policy
๐ Data Retention Policy
๐ค AI & Data Handling
๐ง
AI Provider
Anthropic Claude with Zero Data Retention (ZDR) policy. Prompts are never used for training.
๐ซ
Zero Data Retention
Your data is not retained by AI providers. ZDR agreement in place with Anthropic.
๐
BYOLLM Option
Enterprise customers can bring their own LLM (Azure OpenAI, Gemini) for full data sovereignty.
๐
Training Data
Your data is never used to train AI models. We have contractual commitments from all AI providers.
๐๏ธ
Data Deletion
All customer data deleted within 30 days of account termination. Deletion certificate available.
๐ข
Data Isolation
Strict multi-tenant isolation via Row Level Security (RLS) in Supabase. Org data never commingled.
๐ข Subprocessors
The following vendors process customer data on our behalf. We maintain Data Processing Agreements with all subprocessors.
| Vendor |
Service |
Location |
Certification |
DPA |
| Anthropic |
AI inference (Claude) |
US |
SOC 2 Type II |
Yes โ |
| Supabase |
Database & Auth |
AWS us-east-1 (US) |
SOC 2 Type II |
Yes โ |
| Netlify |
Web Hosting & Functions |
US |
SOC 2 Type II |
Yes โ |
| Cloudflare |
CDN & WAF |
Global |
SOC 2 Type II, ISO 27001 |
Yes โ |
| Brevo |
Transactional Email |
EU |
ISO 27001 |
Yes โ |
Last updated: August 2026. View full subprocessor registry โ
๐ฌ Ask About Our Security
Ask any question about our security practices, certifications, or data handling.