Compliance
We're a small, early-stage team building infrastructure we're proud of. Here's an honest picture of where we are on compliance today — what's shipped, what's in progress, and what's on the roadmap.
We are not yet SOC 2 certified, do not yet hold a HIPAA BAA program, and have not completed formal GDPR/CCPA assessments with a third-party auditor. We are working through these. This page reflects current reality, not aspirations. If you need specific certifications before signing up, email us — we'll tell you where we actually are.
What's shipped today
Encryption at rest (AES-256 via AWS KMS on all EBS and S3). Encryption in transit (TLS 1.3 enforced, minimum TLS 1.2). Per-sandbox process isolation — each agent runs in its own container with separate filesystem, network namespace, and process tree. Audit logs on all API calls, container starts/stops, and admin actions. Role-based access control. Passwords hashed (bcrypt). Secrets stored separately from application data.
These aren't things we're working toward — they're running in production now. If you need to verify any of them technically, email security@ab0t.com and we'll walk you through it.
SOC 2 Type II
We are currently working through the controls and documentation required for a SOC 2 Type II audit. We have not yet completed the audit. We do not yet have a report to share.
What we are doing: documenting all security controls, implementing a formal change management process, setting up continuous monitoring, and working with an auditor. This takes time done properly — we'd rather do it right than rush a paper exercise.
If your procurement process requires a SOC 2 report before signing, we're not the right fit today. If you're comfortable with a controls summary and a direct conversation with our team, email security@ab0t.com.
Privacy: GDPR and CCPA
We respect data subject rights and handle personal data responsibly. We do not sell personal data. These are commitments we make operationally today, even before formal third-party assessment:
Data subject rights we honor now
- Right to Access: Email privacy@ab0t.com and we'll provide a copy of your personal data within 30 days.
- Right to Erasure: Request deletion of your account and associated data. We'll confirm deletion within 30 days.
- Right to Portability: Export your workspace data from the dashboard at any time.
- Right to Rectification: Update your account data directly in settings, or contact us.
- Opt-out of sale: We do not sell personal data. There is nothing to opt out of.
What we don't yet have
- A formal Data Processing Agreement (DPA) reviewed by EU counsel — this is in progress.
- Standard Contractual Clauses (SCCs) for international transfers — in progress alongside the DPA.
- A third-party GDPR/CCPA audit or assessment.
If you need a DPA to sign a contract, contact privacy@ab0t.com — we can share our draft and discuss timeline.
HIPAA
We do not currently offer a Business Associate Agreement (BAA). If you need to run workloads involving Protected Health Information (PHI), we are not yet the right infrastructure choice.
We are aware of the requirements and have the technical foundations in place (encryption at rest and in transit, audit logging, access controls). Getting to a proper HIPAA BAA program involves legal review, updated policies, and a signed agreement structure — that's on our roadmap but not something we'll rush.
If HIPAA compliance is a hard requirement for you today, email security@ab0t.com — we'll tell you honestly whether we can help and on what timeline.
Data Residency
Today, all infrastructure runs in AWS US-West (us-west-2). We do not currently offer data residency controls or region selection.
If your data must stay within the EU or another specific region, we cannot currently guarantee that. EU region support is on our roadmap. Contact sales@ab0t.com if this is a blocker and we'll discuss what's realistic.
Security Questionnaires
We're happy to complete your security questionnaire. We'll answer honestly — including "not yet" where that's the true answer. Send it to security@ab0t.com. We typically turn these around within 5 business days.
We also support authorized penetration tests for enterprise customers. Contact us to arrange scope and scheduling before testing.
Subprocessors
We use the following third-party providers to deliver the service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Infrastructure (compute, storage, networking) | US-East-1 (Virginia) |
| Stripe | Payment processing | United States |
| Anthropic / OpenAI | Underlying model API (used only when you use our AI features) | United States |
We'll update this list when we add new subprocessors. To get notified, email privacy@ab0t.com.
Roadmap
| Item | Status | Notes |
|---|---|---|
| SOC 2 Type II audit | In progress | Controls documentation underway. No committed date. |
| GDPR Data Processing Agreement (DPA) | In progress | Draft exists. Legal review in progress. |
| HIPAA BAA program | Planned | After SOC 2. No committed date. |
| EU data residency (Frankfurt) | Planned | On infrastructure roadmap. No committed date. |
| Vulnerability disclosure program | In progress | Email security@ab0t.com for responsible disclosure in the meantime. |
Contact
- Security questions: security@ab0t.com
- Privacy / data requests: privacy@ab0t.com
- Compliance / procurement: compliance@ab0t.com
- Enterprise / BAA conversations: sales@ab0t.com
Last updated: May 2026. We update this page when our status materially changes.