SecurityHow Obiguard is built, deployed, and certified

SOC 2 Type II.
ISO 42001.
Independently audited.

Obiguard is built to the same standard we hold our customers' AI to. Our security posture is externally audited, continuously monitored, and reported here.

01 / Certifications

Audited. Not self-attested.

Our SOC 2 Type II and ISO 42001 reports are available to customers under NDA. Contact your account team or email [email protected] to request a copy.
SOC 2 TYPE II

SOC 2 Type II

Annual audit by an independent AICPA-registered firm covering Security, Availability, and Confidentiality trust service criteria. Current report covers the period ending December 2025.

Security · Availability · Confidentiality
ISO 42001

ISO/IEC 42001

AI Management System certification covering our governance platform itself — the controls, processes, and risk management practices we apply to Obiguard as an AI system.

AIMS · AI risk management
NIST AI RMF

NIST AI RMF aligned

Our internal risk management process is aligned to the NIST AI Risk Management Framework — Govern, Map, Measure, Manage — and we publish our alignment documentation on request.

Govern · Map · Measure · Manage
02 / Data handling

Your data stays yours.

In SaaS mode, prompt and response content is processed in-memory and never persisted to disk. Only the policy decision and metadata are written to the Audit Ledger.
01

In-memory processing

In SaaS mode, content is inspected in-memory and not written to disk. We can attest to this with a deployment-time enclave proof on request.

In-memory · no persistence
02

VPC & on-prem

Deploy Obiguard entirely inside your own VPC or on-premises. No content ever leaves your network boundary. Full enclave attestation available.

VPC · on-prem · enclave
03

Vulnerability disclosure

We operate a responsible disclosure programme. To report a vulnerability, email [email protected] with a description and reproduction steps. We target a 72-hour initial response.

72hr initial response
03 / Contact

Security contact.

For vulnerability reports, audit report requests, penetration test facilitation, or general security questions, contact us at [email protected]. PGP key available on request.