BUILDER MODE You're editing your public Trust Portal โ€” changes save to your Supabase org config.
๐Ÿ›ก๏ธ Security & Compliance Trust Portal

AssurAI Security Posture

We take security seriously. Review our certifications, security practices, policies, and data handling commitments below.

SOC 2 In Progress GDPR Compliant HIPAA Ready Zero Data Retention AI 99.9% Uptime SLA
๐Ÿ… Certifications & Compliance
In Progress
SOC 2 Type II
Audit window: Q3 2026
Planned
ISO 27001
Target: Q1 2027
Applicable โœ“
HIPAA
BAA available on request
Compliant โœ“
GDPR
DPA available ยท EU SCCs in place
N/A
PCI DSS
No cardholder data processed

Edit certification statuses (JSON):

๐Ÿ”’ Security Overview
๐Ÿ”
Encryption at Rest
AES-256 via Supabase / AWS
๐Ÿ”’
Encryption in Transit
TLS 1.3 on all connections
๐ŸŒŽ
Data Residency
AWS us-east-1 (US)
๐Ÿ“ˆ
Uptime SLA
99.9% โ€” Status page available
๐Ÿ”
Penetration Testing
Annual โ€” Last: Q1 2026
๐Ÿ›ก๏ธ
Vulnerability Scanning
Weekly automated scans
๐Ÿšจ
Incident Response
<72h notification SLA
๐Ÿ‘ค
Access Control
MFA required ยท RBAC ยท SSO
๐Ÿ’พ
Data Backup
Daily backups ยท 30-day retention

Edit security details (one per line: Icon | Label | Value):

๐Ÿ“‹ Policies
๐Ÿ“„ Privacy Policy
๐Ÿ“„ Security Policy (Summary)
๐Ÿ“„ Acceptable Use Policy
๐Ÿ“„ Data Retention Policy
๐Ÿค– AI & Data Handling
๐Ÿง 
AI Provider
Anthropic Claude with Zero Data Retention (ZDR) policy. Prompts are never used for training.
๐Ÿšซ
Zero Data Retention
Your data is not retained by AI providers. ZDR agreement in place with Anthropic.
๐Ÿ”Œ
BYOLLM Option
Enterprise customers can bring their own LLM (Azure OpenAI, Gemini) for full data sovereignty.
๐Ÿ“š
Training Data
Your data is never used to train AI models. We have contractual commitments from all AI providers.
๐Ÿ—‘๏ธ
Data Deletion
All customer data deleted within 30 days of account termination. Deletion certificate available.
๐Ÿข
Data Isolation
Strict multi-tenant isolation via Row Level Security (RLS) in Supabase. Org data never commingled.
๐Ÿข Subprocessors

The following vendors process customer data on our behalf. We maintain Data Processing Agreements with all subprocessors.

Vendor Service Location Certification DPA
Anthropic AI inference (Claude) US SOC 2 Type II Yes โœ“
Supabase Database & Auth AWS us-east-1 (US) SOC 2 Type II Yes โœ“
Netlify Web Hosting & Functions US SOC 2 Type II Yes โœ“
Cloudflare CDN & WAF Global SOC 2 Type II, ISO 27001 Yes โœ“
Brevo Transactional Email EU ISO 27001 Yes โœ“

Last updated: August 2026. View full subprocessor registry โ†’

๐Ÿ’ฌ Ask About Our Security

Ask any question about our security practices, certifications, or data handling.

๐Ÿ‘‹ Hi! I'm AssurAI's security assistant. Ask me anything about our security posture, certifications, data handling, or compliance programmes.