01Trust model
Default deny. Customer-isolated by design. No customer-data-in-training, ever.Assay was architected against three assumptions: (a) customer commercial knowledge is sensitive enough that breach is unacceptable; (b) foundation-model providers are part of the trust boundary and must be contractually constrained; (c) the EU AI Act and equivalent frameworks will treat audit logs as evidentiary records. Our controls are designed to satisfy all three.
02Encryption
TLS 1.3 in transit. AES-256 at rest. Customer-isolated keys with 90-day rotation.All network traffic — client to platform, service to service, and platform to sub-processors — uses TLS 1.3 with modern cipher suites only. HSTS is preloaded on all customer-facing domains. Data at rest is encrypted with AES-256 using tenant-scoped envelope encryption. Data-encryption keys are rotated every 90 days. Enterprise customers can bring their own keys via AWS KMS or GCP CMEK; we surrender access to encrypted material if a customer revokes their key.
03Access control
SSO and SCIM on every paid tier. Role separation enforced at the system level.SAML 2.0 and OpenID Connect SSO are available on every paid tier; SCIM 2.0 provisioning is standard on Enterprise. Role-based access control inside Assay maps directly to the EU AI Act Article 14 segregation-of-duties model: authoring, approval, and publishing of any commercial claim are separate roles enforced at the application layer. Assay employees access customer environments only with documented just-in-time approval; all access is logged and reviewed monthly.
04Tenant isolation
Logical separation everywhere. Physical separation available on Enterprise.The standard architecture provides logical tenant isolation: each customer's Truth Graph, content, and inference logs are scoped to a tenant ID enforced at every layer of the application and database, with row-level security and per-tenant encryption keys. Enterprise customers can elect single-tenant deployments with dedicated compute and storage in either US or EU regions.
05AI safety
No customer content in training. Prompts and outputs retained for audit, not for model improvement.No customer content — including prompts, retrieved sources, generated outputs, or Truth Graph nodes — is used to train, fine-tune, or evaluate foundation models, ours or our sub-processors'. This is contractually enforced with every model provider in our supply chain and verified annually. We retain prompts and outputs for audit purposes per EU AI Act Article 19; that retention is fully separable from any model-training pathway.
06Vulnerability management
SAST + DAST on every PR. Dependency scanning on every build. Annual third-party pen test.Every pull request runs static and dynamic application-security scans before merge. Dependencies are scanned continuously; high-severity findings block deployment. We engage an independent security firm to conduct a black-box penetration test annually; findings are remediated against a published SLA (critical: 7 days, high: 30 days, medium: 90 days) and the executive summary is available to customers under NDA.
07Incident response
Customer notification within one hour of confirmation. Post-mortem within five business days.If we confirm an incident affecting customer data or service availability, we notify the affected customer's primary security contact within one hour, with a status update at least every four hours until resolution. A written post-mortem — including root cause, scope, customer impact, and remediation steps — is published to the affected customer and to our Trust page within five business days. We do not delay disclosure to investigate reputational consequences.
08Audits + certifications
SOC 2 Type I (complete). SOC 2 Type II (in progress). ISO 27001 (scoped for 2027).SOC 2 Type I was completed in January 2026 by an independent firm. SOC 2 Type II is in audit observation through September 2026; we expect to publish the report in October 2026. ISO 27001 is scoped for 2027. HIPAA-eligible deployment is available to Enterprise customers under a BAA. Reports and BAAs are available under NDA from security@assay.wiki.
09Business continuity
Multi-region backups. RPO 1 hour. RTO 4 hours.Customer data is backed up continuously to a second region in the same jurisdiction (US backups in a second US region; EU backups in a second EU region). Our recovery point objective is one hour and our recovery time objective is four hours. Disaster recovery exercises are conducted twice annually; results are reported to customers on request.
10Responsible disclosure
Report issues to security@assay.wiki. We respond within 24 hours and credit researchers who follow the policy.If you discover a security issue, please email security@assay.wiki with reproduction steps. Do not exploit the issue beyond what is necessary to demonstrate it, and do not access data that is not yours. We acknowledge reports within 24 hours, resolve confirmed issues against the SLAs in section 06, and publicly credit researchers (with their permission) in our annual security report. We do not pursue legal action against good-faith researchers who follow this policy.
11Contact
Reach the right person directly: