Security & Trust Center

Trust is a control set, not a promise.

Our engineering divisions handle regulated medical devices, banking rails, and defense-adjacent hardware. The same discipline applies to everything we run.

ISO 27001 CertifiedSOC2 Type II AttestedHIPAA CompliantGDPR & DPDP ReadyFedRAMP-aligned workflows

Certified security management

ISO 27001-certified ISMS with SOC2 Type II attested controls. Annual third-party penetration tests against our own infrastructure — reports available under NDA.

Zero AI data retention

Client data processed through model APIs runs under zero-retention enterprise agreements. We never train shared models on your proprietary data.

Hardware root of trust by default

Devices we ship enforce secure boot with TPM 2.0 or dedicated secure elements, signed firmware images, and encrypted storage out of the box.

Post-quantum readiness

Active research into lattice-based key encapsulation on constrained silicon means your crypto roadmap already accounts for harvest-now-decrypt-later.

Responsible disclosure

We pay for credible vulnerabilities in anything we ship — including our own site and tooling. Reports with reproduction steps go to [email protected]; we acknowledge within two business days and coordinate public disclosure after remediation. Our threat research team has disclosed 42 zero-days to vendors under this same etiquette.

Request compliance documentationPGP key & SOC2 report bridge available under NDA