Trust, stated plainly.
This page describes how XAIGuard is secured, what we comply with today, how we handle your data, and how to report a vulnerability. Where something is not finished, we say so — here, in writing.
Last updated: August 2026
How the platform itself is defended
The controls below are live in production today — not roadmap items.
Multi-tenant isolation
Every customer operates in an org-scoped tenancy enforced by row-level security at the database layer. One organisation can never read another's data, policies or evidence.
Encrypted model credentials
Customer model credentials are encrypted at rest and decrypted only server-side, in memory, at the moment of use. They are never returned to the browser.
TOTP multi-factor authentication
All console access supports time-based one-time passcode MFA. We recommend enforcing it for every seat.
Role-based access control
Five roles — from read-only auditor to full administrator — govern who can view, change and export. Privileges are checked server-side on every request.
Session inactivity timeouts
Idle sessions expire automatically, limiting the window in which a lost device or unattended workstation can be misused.
Full audit logging
Administrative actions, policy changes and evidence exports are recorded in an append-only audit log you can review and export.
Framework mappings shipped today
XAIGuard maps runtime controls and evidence to the frameworks below, out of the box.
Certification status
SOC 2 Type II — in progress.
We publish it here when issued. We do not claim certifications we do not hold.
What we store, and for how long
What we store
Account and identity data for your users, the policies you configure, policy verdicts and enforcement events, prompts and responses you choose to log, and evidence records generated from them. You control logging scope per policy.
Retention
Retention is set per contract and confirmed in your data processing agreement; account records last for the life of the relationship, and logs, verdicts and evidence records for the period defined in your order form. The current schedule is provided on request.
Sub-processors
We use only the infrastructure and communication providers required to run the service, each under written data processing terms. The current sub-processor list is provided on request, and we notify customers before any change that affects their data.
Data residency
Deployment region and residency options are confirmed in writing during procurement, before you commit, and recorded in your order form.
Found something? Tell us.
Report a vulnerability
Email security@xaiguard.com with a description, reproduction steps and any supporting evidence. Please do not disclose publicly until we have had a reasonable opportunity to respond and remediate.
Response commitment: We acknowledge every report and keep the reporter updated until it is resolved or closed, including our remediation timeline once triage is complete.
Safe harbour
We will not pursue legal action against researchers who act in good faith: follow this policy, avoid accessing or modifying data that is not yours, do not degrade service for other customers, and give us reasonable time to fix before disclosing.
Questions our security team can answer.
Architecture deep-dives, penetration-test summaries under NDA, and procurement security reviews.
Verified by what we ship, not what we claim