Enterprise-Grade Security
Your organizational data deserves the highest level of protection. Here's how we safeguard every assessment, recording, and insight.
Security Practices
Encryption
- AES-256 encryption for all data at rest
- TLS 1.3 for all data in transit
- Encrypted database backups
- Secure key management with automatic rotation
Authentication & Access
- Multi-factor authentication support
- Role-based access control (RBAC)
- Session management with automatic expiry
- Rate limiting on all API endpoints
Infrastructure
- US-based cloud infrastructure (Supabase + Netlify)
- Automated security patching
- DDoS protection
- Regular penetration testing
Monitoring & Logging
- Real-time security event monitoring (Sentry)
- Complete audit trails for all operations
- Anomaly detection on authentication attempts
- Incident response procedures documented
Data Handling Policies
We believe your data belongs to you. Period.
No AI Training on Your Data
Your assessment data, recordings, and organizational information are never used to train AI models. We use AI providers (Anthropic, OpenAI, Google) under zero-data-retention agreements.
Data Residency
All data is stored in US-based data centers. We can discuss specific data residency requirements for enterprise customers.
On-Demand Deletion
Request complete deletion of your organization's data at any time. We process deletion requests within 30 days and provide confirmation.
Data Minimization
We only collect data necessary for delivering our service. Assessment recordings are processed and can be deleted after SOP generation.
Compliance Roadmap
Our path to industry-leading certifications.
- GDPR-aligned data practices
- Privacy policy & terms of service
- Data encryption at rest and in transit
- Role-based access control
- SOC 2 Type I audit preparation
- Formal information security policy
- Vendor risk assessment program
- Employee security training
- SOC 2 Type I certification
- Bug bounty program launch
- Third-party penetration testing
- Business continuity planning
- SOC 2 Type II certification
- ISO 27001 evaluation
- CCPA compliance verification
- Annual security audits
Responsible AI Commitment
Every AI-generated recommendation, assessment score, and coaching nudge in the Adapt Engine is designed with human oversight at its core. We use AI as an accelerator, not a replacement for human judgment.
Our multi-model architecture (Anthropic Claude, Google Gemini, OpenAI) provides cross-validation of critical insights. No single model makes final decisions. Assessment results are always reviewable and adjustable by human experts.
We maintain strict data boundaries between organizations. Assessment data from one client is never visible to, or used to influence results for, another client.
Have Security Questions?
Our team is happy to discuss your specific security and compliance requirements.
Contact Security Team