Security & Data Protection
Your data security is our highest priority. Here's how we protect it.
Data Handling Principles
We follow strict principles to ensure your data is handled with the utmost care.
Purpose-Limited Processing
We process only the data you provide for the specific diagnostic engagement. Nothing more.
Encryption Everywhere
Data is encrypted at rest (AES-256) and in transit (TLS 1.3) using industry-standard protocols.
US-Based Infrastructure
All data is stored in US-based infrastructure on AWS us-east-1 with enterprise-grade physical security.
Automatic Data Deletion
Data is deleted 30 days after report delivery unless you opt in to ongoing monitoring.
Never Used for AI Training
Your data is never used to train AI models. Period. Your information stays yours.
Never Shared with Third Parties
We never share your data with third parties. Your pay equity data remains strictly confidential.
Compliance & Certifications
We maintain rigorous compliance standards to meet enterprise requirements.
GDPR Compliant
Fully compliant with GDPR requirements. Data Processing Agreement (DPA) provided for all engagements.
SOC 2 Type II
Our parent company AIGuru maintains SOC 2 Type II certification covering security, availability, and confidentiality.
DPA Template
A Data Processing Agreement template is available for review and execution prior to any engagement.
Access Controls
Multiple layers of access control protect your data at every level.
Role-Based Access Control
Access to data is restricted based on role and need-to-know principles.
Comprehensive Audit Logging
All access to client data is logged and auditable for full accountability.
Two-Factor Authentication
Two-factor authentication is required for all team members accessing client systems.
Client-Controlled Access
You can revoke access and request complete data deletion at any time.
Attorney-Client Privilege
- We support engagements directed by your legal counsel to help preserve attorney-client privilege protections.
- Analysis can be structured to preserve privilege. Ask us how.
Incident Response
- 24-hour notification commitment for any data incident affecting your information.
- Detailed incident response plan available on request. Contact us for a copy.
Security Documents
Download or request our security documentation for your review.
Have security questions?
Our team is ready to discuss your security requirements and provide any documentation you need.