TRUST CENTER

Compliance is
Our Baseline.

We operate with the highest standards of security, privacy, and compliance. Your data is your most valuable asset. We treat it that way.

ARCHITECTURE

Zero-Trust by Design.

Our infrastructure is built on the principle of least privilege. Every component, from ingestion pipelines to the LLM inference engine, operates within strict network boundaries and requires explicit authorization.

  • End-to-End EncryptionAES-256 at rest, TLS 1.3 in transit. Keys managed via AWS KMS with automatic rotation.
  • Strict Tenant IsolationLogical separation of all customer data. Dedicated vector namespaces and isolated database schemas.
  • Ephemeral ProcessingLLM inference nodes are stateless. Prompts and completions are never logged or used for training.
Customer VPC / Identity Provider
↓ TLS 1.3 ↓
WUF.AI API Gateway (WAF + Rate Limiting)
↓ Mutual TLS ↓
Ingestion Workers
Stateless
Inference Engine
Zero Retention
↓ AES-256 ↓
Encrypted Storage (Postgres + Vector DB)

Certifications & Standards

Independently audited and verified.

SOC 2 Type II

Audited by an AICPA-accredited firm. Demonstrating continuous control over security, availability, and confidentiality.

Certified

GDPR & CCPA

Full compliance with EU and California data privacy regulations. Flexible data residency options available for Enterprise customers.

Compliant

ISO 27001

Adhering to the international standard for information security management systems (ISMS). Formal certification pending.

In Progress

Security Documentation

Access our latest reports and policies.

SOC 2 Type II Report (2025)

PDF2.4 MB

Penetration Test Summary (Q3 2025)

PDF1.1 MB

Data Processing Addendum (DPA)

PDF450 KB

Subprocessor List

PDF120 KB

Business Continuity Plan

PDF890 KB

Security FAQ

Common questions about our security posture.

Do you train on our data?

No. We strictly isolate customer data. Your data is never used to train our foundation models or shared with other customers. We offer BYOM (Bring Your Own Model) options for enterprise clients requiring absolute isolation.

Where is data stored?

By default, data is stored in US-East (N. Virginia). Enterprise customers can select data residency in EU (Frankfurt) or APAC (Tokyo) to comply with local regulations.

How is encryption handled?

Data is encrypted at rest using AES-256 and in transit using TLS 1.3. Keys are managed via AWS KMS. We also support BYOK (Bring Your Own Key) for enterprise customers.