Trust & Security
We test other people's AI systems for a living, which means our own posture gets held to a higher bar than most. Here's what that looks like in practice, and how to report a problem if you find one.
How we run our own environment
- Least-privilege internal access — engagement data and client artifacts are scoped per-project, not broadly shared across the team.
- MFA enforced on every internal system that supports it, no exceptions for convenience.
- Encryption in transit and at rest for anything we hold on a client's behalf during an engagement.
- Minimal data retention — engagement artifacts (findings, transcripts, test payloads) are retained only as long as the contract requires, then deleted on a defined schedule.
- No standing production access to client systems outside an active, scoped, time-boxed engagement window.
- This website itself is a static site with no backend database — there's no login system or customer data store to compromise on securedai.org itself.
Where we're headed
As a boutique firm, we're building toward formal third-party attestation (SOC 2 Type II) rather than claiming it today. If a specific certification or attestation is a requirement for your procurement process, tell us during scoping — we'll give you a straight answer on timeline rather than a vague one.
Responsible disclosure
If you find a security issue in our own website, infrastructure, or public-facing tools, we want to hear about it before anyone else does.
- Report to security@securedai.org, or see /.well-known/security.txt for the machine-readable version.
- Please include enough detail to reproduce the issue — a proof of concept is welcome, exploitation of it beyond what's needed to demonstrate impact is not.
- We ask for a reasonable window (typically 90 days) to remediate before any public disclosure.
- We won't pursue legal action against good-faith researchers who follow this policy and avoid privacy violations, service disruption, or data destruction.
- Scope: securedai.org and any subdomains we control. Third-party services we use (hosting, email, forms) are out of scope for us to fix, but we'll help route the report if relevant.
Data handling for engagements
When we run an assessment for a client, findings, credentials, and test data are handled under the terms of that specific engagement's contract, not a one-size-fits-all policy. Ask us for our standard data handling addendum during scoping — we'll walk through retention, access, and destruction terms before anything starts.
Questions
Anything not covered here — a vendor security questionnaire, a specific compliance ask, or a request to see our internal policies in more depth — email contact@securedai.org and we'll get back to you within a business day.