Products
Living MapDrift AlertsBacktest ForensicsPath QueriesCustom AxesRisk Maps
Solutions
Compliance OfficersRisk Managers / CROPortfolio ManagersCTOs & Engineering
Developers
DocumentationAPI ReferenceSDKsArchitectureAudit Manifest
Resources
BlogUse CasesCustomer StoriesPressChangelog
Company
AboutFoundersCareersContact
More
PricingTrustEnterprise
Trust & SecuritySOC 2 Type I · Q1 2027

Security your team
can verify.

Compliance is the architecture, not the afterthought. DEINO ships audit-grade defaults from day one — customer-owned LLM keys, signed audit manifests, sovereign deployment. Inspect the live posture before you ever book a call.

SOC 2Type I · Q1 2027
BYO keysYou hold the LLM keys
SovereignEU · LATAM · on-prem
HMACCustomer-signed manifests
security-posture · deino-platform4/5 live
domain:
Data live
TLS 1.3 in transit

All traffic encrypted with TLS 1.3. HSTS enforced at the edge.

Independently verifiable in the security packet · evidence on request.
live in progress· plannedSOC 2 Type I · Q1 2027

Live security posture · switch domain to inspect controls across Data, Identity, Deployment & Compliance.

§ 01Where DEINO runs

Your residency, your cloud.

Four deployment models, one platform. We don’t force our infrastructure on your regulator — choose the topology your compliance team can defend.

Managed SaaS

AWS multi-region — us-east-1, eu-west-1, sa-east-1. Fastest to value, audit-grade defaults from day one. The default for most customers.

Sovereign cloud

GCP EU (europe-west1) or OCI LATAM (São Paulo). Your data residency, your cloud — we don’t force our infrastructure on your regulator.

On-prem Kubernetes

Self-hosted on your own cluster. We ship the manifests; your infra runs them. The audit ledger never leaves your environment.

Air-gapped

Fully offline install with local vLLM — no outbound calls, ever. In production hardening with defense-adjacent partners.

§ 02Security architecture

How we protect your data.

Six load-bearing controls — each one a decision the platform refuses to relax. Not a dashboard bolted onto a chatbot.

i.

Customer-owned LLM keys

BYO Anthropic, OpenAI, Mistral, or local LLM keys. We never see them. Encrypted at rest with customer-managed KMS. Switch providers in 48h via the abstraction.

ii.

Signed audit manifests

Every manifest cryptographically signed with your key. Tamper-evident. Verifiable years later. The audit trail belongs to you, not us.

iii.

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Field-level encryption for PII. Customer-managed keys on Enterprise. HSM-backed for Custom Axes.

iv.

Append-only audit ledger

Cryptographic signing per write. Optional on-prem ledger so audit history never leaves your environment.

v.

Zero-trust by default

SSO required (SAML / OIDC / Okta / Azure AD). SCIM provisioning. Role-based access control with an explicit matrix — no inheritance.

vi.

Reproducible by design

Backtest Forensics reconstructs any past decision, bit-for-bit. The auditor reproduces your rationale on their own infrastructure. No “trust us.”

§ 03Compliance & certifications

Where each framework stands.

No aspirational logos. The real status of every framework we map to — live today, in progress, or on the dated roadmap.

FrameworkStatusDetail
EU AI Act · Annex IIIHigh-risk controls implemented; manifest mapped to Annex III
BCRA AI principlesLATAM Tier-2 bank deployments; sovereign LATAM cloud
GDPR · Article 28Processor terms in standard DPA; 30-day sub-processor notice
SOC 2 Type ITargeted Q1 2027 · kickoff complete · CAIQ Lite on request
SOC 2 Type II·Targeted Q3 2027, following Type I attestation
ISO 27001·2027 roadmap, aligned to the SOC 2 control set
Live today In progress· Roadmap
§ 04Sub-processors

Full transparency.

Our complete sub-processor roster. Customers receive 30-day notice before any addition or change.

Sub-processorPurposeData categoriesLocation
Amazon Web ServicesPrimary cloud infrastructureAllus-east-1 / eu-west-1 / sa-east-1
Oracle Cloud InfrastructureSovereign LATAM deploymentAll (LATAM customers)São Paulo
Google Cloud PlatformEU sovereign deploymentAll (EU customers)europe-west1
CloudflareEdge CDN, DDoS protectionPublic traffic onlyGlobal edge
Anthropic / OpenAI / MistralLLM providers (BYO keys)Customer-controlledCustomer choice
Pipedrive / SalesforceCRMSales contact dataEU / US
Customer.ioLifecycle emailEmail + product event dataUS
Plausible AnalyticsPrivacy-friendly web analyticsAnonymized site trafficEU (Germany)
LinearProduct issue trackingInternal (no customer data)US
§ 05The security packet

What you can request.

One email returns the complete documentation set. No NDA required for the first package; your security team reviews on their own timeline.

§ 06Vulnerability disclosure

Report a security issue.

Found a vulnerability in DEINO? Responsible disclosure protects our customers — and we acknowledge contributors publicly.

Email

security@deino.ai — encrypted via PGP key on request.

Response time

We acknowledge within 24 hours. Triage within 72 hours.

No legal action

We commit not to pursue legal action against good-faith researchers following coordinated disclosure.

Bounty program

Cash rewards for high-severity issues. Public hall-of-fame for all valid reports.

The first audit where we handed over a reproducible decision changed the relationship — from defendant to evidence-provider. Six weeks became six hours.

Compliance Officer · LATAM Tier-2 Bank · name confidential
§ Final

Hand it to your security team.

CAIQ Lite, architecture overview, DPA, sub-processor list, incident response, and continuity plan — the full packet, on request. Reviewed on their timeline, not ours.