SOC 2 Type II — in progress
Underway, not yet certified. Our policy library is available to Enterprise customers today; the auditor's report follows when the audit does.
SSO. SAML 2.0. LDAP + Active Directory. HIPAA mode. Full audit export. Region-pinned data. Dedicated SLA. Every enterprise-grade posture your compliance team needs, on top of the same product your operators already use — no separate admin console, no different data model, no bolted-on chatbot.
Identity + SSO
Okta, Azure AD, Google Workspace, or any OIDC provider. LDAP for legacy directories. SCIM for provisioning.
Compliance
HIPAA mode. BAA on request. Region-pinned data. Sub-processor list + DPA in the same envelope. SOC 2 Type II in progress — status on the compliance page.
Audit + observability
Immutable audit log across every module. Every AI action logged as the delegating operator's action. Monthly SIEM export.
Underway, not yet certified. Our policy library is available to Enterprise customers today; the auditor's report follows when the audit does.
BAA + PHI handling controls turned on org-wide. Encryption at rest + in transit; audit log retention extended; risk assessments quarterly.
Standard-clause DPA + sub-processor list + Art. 20 data export + Art. 17 deletion. EU data-region option.
Payment card handling routed through PCI-compliant gateways (Stripe / Adyen / Braintree / Razorpay). We never touch or store card numbers.
Default. Shared tenancy on our infrastructure; region-pinned; 99.9% SLA. Fastest to onboard.
Dedicated database + storage + workers, still on our infrastructure. Isolation + BYOB + custom retention.
Deploy to your own cloud (AWS, GCP, Azure, on-prem). Kubernetes chart + Terraform module. Under evaluation for Enterprise buyers with strict data-locality requirements.
We keep the packet ready. Sales replies within one business day; a security engineer is on the second call.
One email every ~2 weeks. Honest product notes, no marketing pitches.