Trust center

Trust, stated plainly.

This page describes how XAIGuard is secured, what we comply with today, how we handle your data, and how to report a vulnerability. Where something is not finished, we say so — here, in writing.

Last updated: August 2026

Security posture

How the platform itself is defended

The controls below are live in production today — not roadmap items.

Multi-tenant isolation

Every customer operates in an org-scoped tenancy enforced by row-level security at the database layer. One organisation can never read another's data, policies or evidence.

Encrypted model credentials

Customer model credentials are encrypted at rest and decrypted only server-side, in memory, at the moment of use. They are never returned to the browser.

TOTP multi-factor authentication

All console access supports time-based one-time passcode MFA. We recommend enforcing it for every seat.

Role-based access control

Five roles — from read-only auditor to full administrator — govern who can view, change and export. Privileges are checked server-side on every request.

Session inactivity timeouts

Idle sessions expire automatically, limiting the window in which a lost device or unattended workstation can be misused.

Full audit logging

Administrative actions, policy changes and evidence exports are recorded in an append-only audit log you can review and export.

Compliance

Framework mappings shipped today

XAIGuard maps runtime controls and evidence to the frameworks below, out of the box.

OWASP LLM Top 10NIST AI RMFMITRE ATLASISO/IEC 42001EU AI ActGDPRSEC disclosureAIUC-1

Certification status

SOC 2 Type II — in progress.

We publish it here when issued. We do not claim certifications we do not hold.

Data handling

What we store, and for how long

What we store

Account and identity data for your users, the policies you configure, policy verdicts and enforcement events, prompts and responses you choose to log, and evidence records generated from them. You control logging scope per policy.

Retention

Retention is set per contract and confirmed in your data processing agreement; account records last for the life of the relationship, and logs, verdicts and evidence records for the period defined in your order form. The current schedule is provided on request.

Sub-processors

We use only the infrastructure and communication providers required to run the service, each under written data processing terms. The current sub-processor list is provided on request, and we notify customers before any change that affects their data.

Data residency

Deployment region and residency options are confirmed in writing during procurement, before you commit, and recorded in your order form.

Responsible disclosure

Found something? Tell us.

Report a vulnerability

Email security@xaiguard.com with a description, reproduction steps and any supporting evidence. Please do not disclose publicly until we have had a reasonable opportunity to respond and remediate.

Response commitment: We acknowledge every report and keep the reporter updated until it is resolved or closed, including our remediation timeline once triage is complete.

Safe harbour

We will not pursue legal action against researchers who act in good faith: follow this policy, avoid accessing or modifying data that is not yours, do not degrade service for other customers, and give us reasonable time to fix before disclosing.

Questions our security team can answer.

Architecture deep-dives, penetration-test summaries under NDA, and procurement security reviews.

Verified by what we ship, not what we claim