Trust Center

A risk tool has to be trustworthy itself.

We hold ourselves to the standards we help you enforce on everyone else: enterprise-grade security, privacy by design, and continuous assurance. Here's the detail, no NDA for the basics.

SYSTEM STATUS MONITORED
UPTIME TARGET
99.999%
DATA ENCRYPTED
In transit & rest
Security overview

Our security program is aligned to leading frameworks and built on industry best practices.

Explore compliance
01
Zero Trust
Least-privilege access, segmentation, continuous verification.
02
24/7 Monitoring
Real-time threat detection and security operations.
03
Encryption
In transit and at rest, to industry standards.
04
Access Controls
SAML SSO, MFA, RBAC and regular access reviews.
05
Incident Response
Documented readiness, detection and rapid response.
Compliance

Mapped to rigorous global standards

We operate in alignment with these standards today; formal certifications sit on the roadmap, and we'll tell you exactly where each one stands.

SOC 2 Type II
IN ALIGNMENT
ISO 27001
IN ALIGNMENT
GDPR
ALIGNED
CSA STAR
PLANNED
Compliance roadmap
SOC 2 Type II
PLANNED
2026
ISO 27001
PLANNED
2026
GDPR program
ALIGNED
ONGOING
CSA STAR
PLANNED
2026
ISO 27701
PLANNED
2026

Roadmap reflects current plan and is subject to change.

QUESTIONNAIRES
CAIQ (Consensus Assessments)
Standardized self-assessment, under NDA.
SIG Lite
Shared on request for vendor reviews.
Custom questionnaires
Submit requests to our security team.
Request questionnaires
CLOUD INFRASTRUCTURE
Compliant foundation
Cloud-native, highly available architecture.
High availability
Monitored with automated failover.
Infrastructure as code
Secure, version-controlled deployments.
Infrastructure details
DATA & PRIVACY
Data ownership
You own your data. We never sell it.
Data residency
EU (Frankfurt) or US hosting on Enterprise plans, as a dedicated deployment. UK and UAE regions on the roadmap.
Access & deletion
Full control over your data lifecycle.
Read privacy policy
AI data handling

What Dave sees, and what he never does

Dave is our assessment engine: he reads questionnaire responses and proposes grades. If an AI is going to touch your vendor data, you deserve to know exactly how. Here is exactly how.

01 · WHAT HE SEES

The questionnaire answers being graded and the evidence attached to them. Nothing else from your workspace, and never another customer's data: every tenant is isolated.

02 · WHERE IT RUNS

Inference runs on OpenAI's API, disclosed on our sub-processor list, under API terms that exclude customer data from model training.

03 · NO TRAINING

Neither Altisium nor our AI provider trains models on your data. Your questionnaires improve your assessments, not anyone's model.

04 · HUMAN DECIDES

Dave proposes a grade with its confidence and the evidence he cited. Your reviewer accepts or overrides it, and every decision keeps a full audit trail.

Questions about the AI pipeline? Ask the security team. Real answers, not a black box.

Documentation

Assurance, in detail

PEN TESTING
Continuous vulnerability scanning
Third-party assessments
Penetration testing on the assurance roadmap
Remediation & verification
SECURE BY DESIGN
Secure SDLC practices
Code reviews & static analysis
Dependency scanning
Secrets management
AVAILABILITY
Availability by design
A 99.999% uptime target, monitored around the clock.

Questions about security, or need custom assurance?

Our security team responds fast. Enterprise-focused, no runaround.

Contact security team