Hi — I'm Aigenta 👋 Need an appointment or have a question? I can help right here.
Security

How we protect your data.

An overview of our security program. Full reports and our SOC 2 are available under NDA from [email protected].

Encryption
TLS 1.3 in transit. AES-256 at rest. Per-tenant encryption keys managed in AWS KMS.
SOC 2 Type II
Annual audit by a Big Four firm. Report available under NDA.
EU data residency
All EU customer data stored in Frankfurt (eu-central-1). Optional US residency on Scale.
Isolated tenants
Logical tenant isolation enforced at the database level. Per-tenant encryption keys.

Program overview

Our security program follows ISO 27001 controls and is audited annually for SOC 2 Type II. We run quarterly penetration tests, monthly vulnerability scans, and weekly dependency reviews. Findings are tracked publicly to our customers on Scale.

Access control

SSO (SAML 2.0 and OIDC) on the Scale plan. TOTP-based 2FA on all paid plans. Internal access is just-in-time, requires hardware keys, and is logged. We follow the principle of least privilege — most engineers cannot access customer data without an approved JIT request.

Data handling

We process customer data only to provide the service. We do not train AI models on your conversations or your customers' conversations. We use third-party LLM providers (currently Anthropic) under zero-data-retention contracts; their API responses are not retained beyond the request.

Incident response

24/7 on-call rotation. We notify affected customers of confirmed security incidents within 72 hours of discovery, per GDPR Article 33 and our Master Services Agreement.

Responsible disclosure

We welcome reports from security researchers. Submit findings to [email protected] (PGP key on keys.openpgp.org). We commit to a 48-hour first response, a 30-day patch SLA for critical findings, and public acknowledgment if you'd like one.

Sub-processors

The current list with locations, purposes, and DPAs is at /dpa. We notify customers 30 days before adding a new sub-processor.

Compliance & reports

  • SOC 2 Type II — annual
  • ISO 27001 — controls aligned, certification in progress
  • GDPR & CCPA — full compliance program; DPA at /dpa
  • HIPAA — available on Scale with signed BAA