Trust & Security

Enterprise-Grade Security

Your organizational data deserves the highest level of protection. Here's how we safeguard every assessment, recording, and insight.

Security Practices

Encryption

  • AES-256 encryption for all data at rest
  • TLS 1.3 for all data in transit
  • Encrypted database backups
  • Secure key management with automatic rotation

Authentication & Access

  • Multi-factor authentication support
  • Role-based access control (RBAC)
  • Session management with automatic expiry
  • Rate limiting on all API endpoints

Infrastructure

  • US-based cloud infrastructure (Supabase + Netlify)
  • Automated security patching
  • DDoS protection
  • Regular penetration testing

Monitoring & Logging

  • Real-time security event monitoring (Sentry)
  • Complete audit trails for all operations
  • Anomaly detection on authentication attempts
  • Incident response procedures documented

Data Handling Policies

We believe your data belongs to you. Period.

No AI Training on Your Data

Your assessment data, recordings, and organizational information are never used to train AI models. We use AI providers (Anthropic, OpenAI, Google) under zero-data-retention agreements.

Data Residency

All data is stored in US-based data centers. We can discuss specific data residency requirements for enterprise customers.

On-Demand Deletion

Request complete deletion of your organization's data at any time. We process deletion requests within 30 days and provide confirmation.

Data Minimization

We only collect data necessary for delivering our service. Assessment recordings are processed and can be deleted after SOP generation.

Compliance Roadmap

Our path to industry-leading certifications.

CurrentComplete
  • GDPR-aligned data practices
  • Privacy policy & terms of service
  • Data encryption at rest and in transit
  • Role-based access control
Q2 2026In Progress
  • SOC 2 Type I audit preparation
  • Formal information security policy
  • Vendor risk assessment program
  • Employee security training
Q4 2026
  • SOC 2 Type I certification
  • Bug bounty program launch
  • Third-party penetration testing
  • Business continuity planning
2027
  • SOC 2 Type II certification
  • ISO 27001 evaluation
  • CCPA compliance verification
  • Annual security audits

Responsible AI Commitment

Every AI-generated recommendation, assessment score, and coaching nudge in the Adapt Engine is designed with human oversight at its core. We use AI as an accelerator, not a replacement for human judgment.

Our multi-model architecture (Anthropic Claude, Google Gemini, OpenAI) provides cross-validation of critical insights. No single model makes final decisions. Assessment results are always reviewable and adjustable by human experts.

We maintain strict data boundaries between organizations. Assessment data from one client is never visible to, or used to influence results for, another client.

Have Security Questions?

Our team is happy to discuss your specific security and compliance requirements.

Contact Security Team