security trust is the product
Built to be trusted with your work.
Agents touch your inbox, your docs, your customer data. That only works if the answer to “is it safe?” is boringly, verifiably yes. Your data stays yours: encrypted by default, isolated per tenant, and never used to train AI models.
Encryption everywhere
- — TLS 1.2+ forced on every connection — HTTPS only, HSTS enabled.
- — AES-256 at rest across databases, files, and backups.
- — Keys managed and rotated in a dedicated KMS; secrets never live in code.
Infrastructure & residency
- — Runs on AWS across multi-AZ deployments in India, the US, and the EU.
- — You pick your workspace region at signup — content stays in it.
- — Encrypted backups on a rolling 90-day window; DR tested annually.
Access control
- — SSO (SAML 2.0), SCIM provisioning, and enforced 2FA on Team plans and up.
- — Role-based access with per-agent permission scoping and full audit logs.
- — Internal production access is least-privilege, logged, and reviewed quarterly.
AI data governance
- — Your content never trains our models — or anyone else’s.
- — Zero-data-retention agreements with model providers: not logged, not stored.
- — No cross-tenant mixing during AI processing. Agents act only inside the permissions you grant.
Monitoring & testing
- — Independent penetration tests at least annually; summaries available under NDA.
- — Continuous vulnerability scanning, dependency audits, and CI-enforced static analysis.
- — Centralised logging with anomaly alerting and a 24/7 on-call rotation.
Reliability
- — 99.9% uptime target, tracked publicly on our status page.
- — Multi-AZ failover; self-healing workflows retry around provider outages.
- — Incident process with public post-mortems for anything user-facing.
responsible disclosure
Found something? Tell us first.
We value the work of security researchers. If you find a vulnerability in definable.ai, our app, or our APIs, report it to [email protected] with steps to reproduce. We acknowledge reports within 48 hours, keep you updated through the fix, and credit researchers who want it.
Safe harbor: we will not pursue legal action against researchers who act in good faith — access only what is needed for a proof of concept, avoid service disruption and other users’ data, and give us reasonable time to fix before disclosing publicly.
asked by every security review
The questionnaire, pre-answered.
Need the documents themselves — SOC 2 report, pentest summary, ISO certificate, signed DPA? One email, under NDA, two business days.
[email protected]legal details live in the privacy policy and dpa
Is my data used to train AI models?
No. Never, on any plan. Our agreements with model providers prohibit training on your content and require zero data retention where offered — your prompts and outputs are not logged for human review and not saved to disk on their side. The commitment is contractual: see our DPA, Annex 3.
Where is my data stored?
In the region you choose at signup — India, the US, or the EU — on AWS. Workspace content does not leave your region except when a workflow routes a task to a model provider you have enabled, and then only the content needed for that task.
Can I get your SOC 2 report?
Yes. The current SOC 2 Type II report, ISO 27001 certificate, and latest pentest summary are available under NDA. Email [email protected] and we typically turn access around within two business days.
How do agent permissions work?
Every integration is connected with explicit OAuth scopes, and every agent action class (read, draft, send, write) can be gated behind approval. Audit trails record every action each agent takes, with the workflow, model, and instruction that triggered it.
What happens to my data if I leave?
You can export everything self-serve, and the export window stays open 30 days after termination. After that we delete from production within 30 days and from backups within 90. Deletion confirmation available on request.
Do you support SSO and SCIM?
SAML 2.0 SSO and SCIM provisioning are available on Team plans and above. Google and GitHub sign-in are available on all plans, and 2FA can be enforced workspace-wide.