Trust
We hold the line we sell.
An AI enforcement vendor that loses its own audit log has no business shipping. Here's how we run.
Controls
How we protect the platform.
Encryption everywhere
TLS 1.3 in transit. AES-256 at rest. Customer-managed keys on Enterprise.
Tamper-evident audit
Decision log is hash-chained and signed. Tampering is detectable from any single record.
Workspace isolation
Per-workspace keys, per-workspace policy bundles, per-workspace audit.
Least privilege
No standing production access. Every elevated session is approved and recorded.
Sovereign deployment
Run BoundaryAI in your VPC or fully air-gapped. No telemetry leaves.
Continuous red-team
Internal and external adversarial testing on every release.
Compliance
Certifications and frameworks.
SOC 2 Type II
Annual audit. Report available under NDA.
ISO 27001
Information security management system. Coming Q3 2026.
HIPAA / BAA
Available on Enterprise. PHI handling controls active by default.
GDPR / DPA
Standard DPA on all paid plans. EU data residency available.
Security questionnaires welcome.
Send your favorite 400-row spreadsheet. We'll return it within the week.