Trust Center
Certifications & Compliance
SUPERWISE maintains industry-leading security certifications and undergoes regular third-party audits.
SOC 2 Type II
Annual audit of security, availability, and confidentiality controls
Last audit: December 2024
GDPR
Compliance with European data protection requirements supporting responsible AI and data governance practices.
Last audit: Ongoing
HIPAA
Safeguards and controls supporting protected healthcare information and regulated AI workloads.
Last audit: December 2024
ISO 27001
Information security management system certification
Last audit: November 2024
Security Controls
Multi-layered security architecture protecting infrastructure, applications, data, and AI operations throughout the lifecycle.
Encryption
All data encrypted at rest (AES-256) and in transit (TLS 1.3). Customer data keys managed via AWS KMS with automatic rotation.
- AES-256 at rest
- TLS 1.3 in transit
- AWS KMS key management
- Automatic key rotation
Infrastructure
Deployed on SOC 2 compliant cloud infrastructure with multi-region redundancy and automatic failover.
- AWS & GCP hosting
- Multi-region deployment
- 99.99% uptime SLA
- Automatic failover
Access Control
Granular role-based access controls, enterprise identity integrations, and comprehensive audit logging support secure governance of AI systems and operational workflows.
- RBAC with custom roles
- SSO/SAML integration
- MFA enforcement
- Audit logging
Secrets Management
Dedicated secrets management and automated credential rotation reduce risk while supporting secure AI and application operations.
- HashiCorp Vault
- No plaintext storage
- Automatic rotation
- Least privilege
Vulnerability Management
Continuous monitoring, vulnerability scanning, penetration testing, and remediation processes help maintain a strong security posture across evolving AI environments.
- Daily dependency scans
- Quarterly pen tests
- Bug bounty program
- 24hr critical patches
Incident Response
Formal incident response processes, 24/7 monitoring, and predefined escalation procedures support rapid detection, containment, and recovery.
- 24/7 security team
- < 1hr P0 response
- Runbook automation
- Post-incident reviews
Security Documentation
Access security, compliance, and governance documentation to accelerate vendor reviews, procurement assessments, and enterprise AI evaluations. Some materials require NDA approval.
SOC 2 Type II Report
Independent auditor report on security, availability, and confidentiality controls.
NDA RequiredSecurity Whitepaper
Technical overview of SUPERWISE security architecture and controls.
PublicPenetration Test Summary
Executive summary of most recent third-party penetration test.
NDA RequiredData Processing Agreement
Standard DPA for GDPR compliance.
PublicSIG Lite Questionnaire
Pre-filled Standardized Information Gathering questionnaire.
Available on RequestBusiness Continuity Plan
Overview of disaster recovery and business continuity procedures.
NDA RequiredRequest Security Documentation
Request access to compliance reports, security assessments, architecture documentation, and governance materials to support your enterprise evaluation process.
What You'll Receive
- SOC 2 Type II audit report (under NDA)
- Penetration test executive summary
- Pre-filled SIG/CAIQ questionnaire
- Architecture & data flow diagrams
- AI governance and operational security documentation
Security questions?
security@superwise.aiReady to Evaluate SUPERWISE?
Our team is here to support your security evaluation process.
Explore More AI Governance Resources
Explore AI governance insights, platform resources, implementation guidance, and enterprise success stories.