Security · Trust · Compliance

Security & trust

Built for regulated industries. Sertainly is the governed, auditable decision layer — encrypted end‑to‑end, deployable inside your boundary, and deterministic by design, with zero AI at runtime.

The questions security teams ask

ConcernSertainly
Is my case data sent to an LLM at runtime?No. Runtime is a deterministic engine — zero LLM inference. Case data is never sent to a model to decide.
Is my policy or source data used to train models?No. We never train on your content.
Can I use my own AI provider credentials?Yes — bring your own keys for the build-time AI.
Can I deploy inside my own boundary?Yes — managed multi-tenant, dedicated, VPC, or air-gapped on-prem.
Are decision packages signed and versioned?Yes — every published package is hashed, signed, and version-pinned.
Can past decisions be replayed and audited?Yes — an immutable trace plus full decision replay.
How is access controlled?SSO via SAML, OIDC, and SCIM, with role-based access control.
What is your SOC 2 status?SOC 2 Type II — audit in progress.
Is a DPA and subprocessor list available?Yes — DPA available; subprocessor list on request.
Built for regulated enterprises

SOC 2 Type II

Audit in progress. Encryption in transit and at rest across every deployment model.

Enterprise SSO

SSO via SAML and OIDC, with role-based access control across environments.

Flexible deployment

Managed, dedicated, VPC, on‑prem, or fully air-gapped — data stays inside your boundary.

DPA available

A Data Processing Agreement is available, with GDPR-aligned data handling.

Data protection

Your content is yours. We handle it under strict, contractually-backed commitments — and give you the option to keep AI processing entirely under your own credentials.

We never sell your data

We do not sell, rent, or license your content or personal information to anyone. Ever.

No training on your content

Your content is never used to train, fine-tune, or improve any AI model — ours or anyone else's. Our AI subprocessors are contractually prohibited from training on data we send on your behalf.

Bring your own AI credentials

Configure Sertainly to use your own AI provider credentials so build-time AI calls route directly from your account to that provider, under your own contract with them.

Encryption everywhere

Encryption at rest using AES‑256 and TLS in transit, across every deployment model.

Deterministic by design

AI assists when you build a decision package. At runtime, there is no model inference at all — every decision is pure, reproducible computation. That is a security and privacy property, not just a performance one.

Zero LLM inference at runtime

Decisions run on a deterministic engine. No prompts, no model calls, no probabilistic reasoning at evaluation time — so your case data is never sent to a model to make a decision.

Reproducible & auditable

Same input, same output, every time. Any decision can be replayed exactly, years later, with the same result — no drift, no guesswork.

Signed, immutable artifacts

Every published decision package is a signed, immutable build artifact. Tampered artifacts never execute.

Deployment & isolation

Run Sertainly wherever your compliance posture requires. The same engine, the same decisions — inside your network boundary.

Managed multi-tenant

Fully managed by Sertainly with per-tenant isolation, encryption, and RBAC.

Dedicated

A single-tenant instance with full network isolation and its own encryption boundary.

Your cloud (VPC)

Deploy into your own AWS account. Data never leaves your network boundary.

On-prem & air-gapped

Fully air-gapped deployments for the most tightly regulated environments — no external calls.

Governance & audit

Audit — trace everything

  • Immutable audit trail of every decision, with full input, output, and trace
  • Full decision replay — reconstruct any past decision exactly
  • Signed, versioned build artifacts with complete provenance

Control — operate safely

  • Role-based access control with environment-scoped permissions
  • SSO via SAML and OIDC through your own identity provider
  • Approval and promotion gates before anything reaches production

Compliance

We keep our claims honest. Here is exactly where we stand today.

SOC 2 Type II

In progress. Our audit is underway; we are happy to walk security teams through current status and controls.

Data Processing Agreement

A DPA is available for customers who need one as part of their procurement process.

GDPR-aligned handling

Data handling is aligned with GDPR principles, backed by data subject rights and lawful transfer mechanisms.

Infrastructure & subprocessors

Infrastructure runs on AWS. Authentication is provided by Clerk and billing by Stripe. AI model inference is used only at build time, and only when you rely on Sertainly-provided AI credentials. See our Privacy Policy for the full list of subprocessors.

Bring your security team.

We will walk through our controls, deployment options, and compliance status — and answer your security questionnaire.

Talk to securityBook a demo