Security
Security controls — what we have, what we don't.
We don't claim certifications we haven't earned. This page describes what Inferpathio's infrastructure actually does: encryption, access control, audit log integrity, and data handling. We also tell you directly what we don't have yet and what we're working toward.
Controls
Security controls overview
Encryption
- AES-256 encryption at rest for all stored data
- TLS 1.3 in transit for all API and dashboard traffic
- Separate key management per customer tenant
Access Control
- Role-based access control (RBAC) with per-model scoping
- SSO via SAML 2.0 (Okta, Azure AD, Google Workspace)
- API key scoping — read-only, write, admin tiers
Audit Logs
- Immutable audit log — no modification or deletion by any role
- All governance events logged with full actor + policy metadata
- Export via REST API or CSV for SOC 2 review packages
Data Handling
- Feature vector PII isolation — consent-layer hooks supported
- Tenant data isolation — no cross-tenant data access possible
- On-premise data residency options for Enterprise plans
Security FAQ
Common security questions
Starter plans: 90-day audit log retention. Team plans: 1 year. Enterprise plans: configurable retention up to unlimited with dedicated storage. SDK metadata and model registry data are retained for the life of the account plus 30 days post-cancellation.
API keys are hashed on creation — Inferpathio never stores plaintext keys. Keys can be scoped (read-only, write, admin) and rotated or revoked at any time from the dashboard. All key usage is logged in the audit trail. We support short-lived tokens for CI/CD environments via the REST API.
Enterprise plans include on-premise data residency options for audit logs and model metadata in your cloud environment (AWS, GCP, or Azure VPC). The governance orchestration layer runs as a managed service. Full on-premise deployment is on our roadmap for 2027. Contact sales for current options.
We conduct external penetration tests annually and internal security reviews quarterly. Results inform our security roadmap but are not published publicly. Enterprise customers can request a summary of most recent external pen test findings under NDA as part of the procurement process.
Inferpathio is not currently SOC 2 certified. Our infrastructure is built with SOC 2 Type II controls in mind — encryption at rest and in transit, RBAC, immutable audit logs, incident response procedures, and vulnerability management. We walk Enterprise customers through our control documentation during security reviews. SOC 2 Type II certification is planned for late 2026.
Email [email protected] with the subject line "Security Vulnerability Report". We aim to acknowledge within 24 hours and provide a resolution timeline within 5 business days. We do not currently have a formal bug bounty program, but we'll recognize significant findings in our public changelog with your permission.