Trust

We hold the line we sell.

An AI enforcement vendor that loses its own audit log has no business shipping. Here's how we run.

Controls

How we protect the platform.

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Customer-managed keys on Enterprise.

Tamper-evident audit

Decision log is hash-chained and signed. Tampering is detectable from any single record.

Workspace isolation

Per-workspace keys, per-workspace policy bundles, per-workspace audit.

Least privilege

No standing production access. Every elevated session is approved and recorded.

Sovereign deployment

Run BoundaryAI in your VPC or fully air-gapped. No telemetry leaves.

Continuous red-team

Internal and external adversarial testing on every release.

Compliance

Certifications and frameworks.

SOC 2 Type II
Annual audit. Report available under NDA.
ISO 27001
Information security management system. Coming Q3 2026.
HIPAA / BAA
Available on Enterprise. PHI handling controls active by default.
GDPR / DPA
Standard DPA on all paid plans. EU data residency available.

Security questionnaires welcome.

Send your favorite 400-row spreadsheet. We'll return it within the week.