Security & Trust Center
Your data security is our foundation. Enterprise-grade protection at every layer of the platform.
Built to industry-recognized security standards.
ARK supports SOC 2 Type II and ISO 42001. Our certification program is underway, with independent audit scheduled for September 2026. We publish our status as it stands, not as we would like it to look.
SOC 2 Type II
Infrastructure supporting SOC 2 Type II, with controls mapped to the trust services criteria for availability, confidentiality, and processing integrity. Our audit is scheduled for September 2026.
ISO 42001 Supported
AI management system controls mapped to the ISO 42001 standard for responsible AI governance. Independent audit scheduled for September 2026.
GDPR Compliant
Full compliance with EU General Data Protection Regulation, including data processing agreements.
Zero AI Data Retention
Contractual zero data retention with every AI provider. Your documents and queries are never used to train models.
ICO Registered
Registered with the UK Information Commissioner's Office as a data processor and controller.
Defense in depth.
AES-256 Encryption at Rest
All stored data is encrypted using AES-256, including documents, embeddings, metadata, and audit logs.
TLS 1.3 in Transit
All data in transit is protected with TLS 1.3. Certificate pinning is available for enterprise deployments.
Multi-Factor Authentication
MFA enforcement across all user accounts, with support for hardware security keys (FIDO2).
SSO Integration
SAML 2.0 and OIDC single sign-on with your existing identity provider: Azure AD, Okta, Google Workspace.
Role-Based Access Control
Granular RBAC ensuring users only access data they are authorized to see. Inherited from your identity provider.
Complete Audit Trails
Every query, response, and data access event is logged with timestamps, user identity, and source references.
Zero data retention with AI providers.
ARK enforces strict data handling policies with all AI providers. Your documents and queries are never stored by third-party AI services and are never used to train models. Every response is grounded in your data, with full provenance.
- Zero data retention: queries are ephemeral
- No model training on your data: guaranteed by contract
- Grounded responses: every answer cites source documents
- Provenance tracking: full audit trail for AI interactions
- Data Processing Agreements with all AI sub-processors
Your infrastructure, your rules.
Choose the deployment model that matches your security and compliance requirements.
Our Cloud
Fully managed on Ageiro infrastructure. AWS-hosted with multi-region availability, automated backups, and 99.5% uptime SLA. Fastest time to value.
Ageiro manages ~90% of the stack
Your Cloud
Deployed within your AWS, Azure, or GCP environment. Your data never leaves your tenancy. Shared responsibility model with Ageiro managing the application layer.
~50/50 shared responsibility
On-Premise
Complete network isolation within your own data center or private cloud. This is not a standard, self-serve option. We scope it with you case by case, so please contact us for further details.
Scoped with you before anything is agreed
Responsible disclosure process.
We welcome responsible security research. If you discover a vulnerability, please follow our disclosure process.
Report
Submit vulnerability details to security@ageiro.global with a clear description and reproduction steps.
Acknowledge
We acknowledge receipt within 2 business days and assign a severity classification.
Investigate
Our security team investigates, validates, and develops a fix. We keep you updated on progress.
Resolve
We deploy the fix, verify the resolution, and notify the reporter. Critical issues are addressed within 72 hours.
Report vulnerabilities to
security@ageiro.global
Please do not disclose vulnerabilities publicly until we have resolved the issue.
Security questions.
Questions about security?
Our security team is happy to discuss your specific requirements and compliance needs.
