Trust
Security, stated plainly.
Our buyers handle the most sensitive data in their country. That earns a straight answer about what we do, and about what we have not done yet.
Data stays where you put it
Air-gapped and on-premises deployments hold your data inside your perimeter. We do not require a vendor cloud, and we do not phone home from an air-gapped build.
Your keys
Encryption in transit and at rest, with key custody on your side in on-premises and sovereign deployments.
Role-based access
Access is scoped per case, per source, and per role. Analysts see what their authority covers, and every view is logged.
Tamper-evident audit
Hashing and timestamping on evidence, and an append-only audit trail across collection, analysis, and export.
No training on your data
Customer data is never used to train or fine-tune models. AI features process only what a task requires, inside your deployment.
Certification roadmap
We hold no security certification today and will not imply one. ISO 27001 and SOC 2 are on the roadmap, and we will contract to specific milestones rather than describe an aspiration.
Reporting a vulnerability
Report findings through our contact form, marking the message as a security report. We do not publish mailboxes, so the form is the route in. Our machine-readable policy is at /.well-known/security.txt. We will acknowledge a report and keep you updated through to resolution.