Security

How we protect your data and infrastructure — and where we are on certifications

Honest baseline

We're an early-stage company. We have strong technical controls in production. We do not yet hold SOC 2 Type II, HIPAA BAA, or formal third-party certifications. This page is accurate — the technical controls are real and running. The certifications are in progress. See compliance page for full status.

TLS 1.3 AES-256 at rest Container isolation Audit logs

1. Infrastructure Security

Container Isolation

Each sandbox runs in its own container — separate process namespace, network namespace, and ephemeral filesystem. Tenants cannot affect each other.

Live

AWS Infrastructure

Hosted on AWS (us-west-2). VPC isolation, security groups, private subnets. No traffic crosses tenant boundaries.

Live

Encryption

TLS 1.3 in transit (min TLS 1.2). AES-256-GCM at rest via AWS KMS. Automatic key rotation.

Live

Audit Logging

All API calls, container lifecycle events, and admin actions are logged with user_id, org_id, and timestamp. Retained 90 days.

Live

2. Container Security

2.1 Isolation Model

Each container benefits from multiple isolation layers — all of these are live in production:

2.2 Image Security

3. Network Security

3.1 Inbound

3.2 Outbound Controls

4. Authentication & Access Control

4.1 User Authentication

4.2 Internal Access

5. Data Protection

5.1 Encryption

In Transit TLS 1.3 (min TLS 1.2)
At Rest AES-256-GCM via AWS KMS
Key Management AWS KMS — automatic annual rotation
Secrets AWS Secrets Manager

5.2 Data Handling

6. Certifications & Compliance Status

Honest status as of May 2026:

SOC 2 Type II

Controls documentation underway. Audit not yet complete. No report available.

In Progress

GDPR / CCPA

Data subject rights honored operationally. DPA in legal review. No third-party audit yet.

Practices in place

HIPAA / BAA

BAA program not yet available. Do not run PHI workloads until this is in place.

On roadmap

Penetration Testing

Internal testing ongoing. Third-party pentest not yet scheduled.

In Progress

See our compliance page for the full roadmap and detail on each item.

7. Vulnerability Management

8. Incident Response

We take incidents seriously. Current capabilities:

9. Responsible Disclosure

Found a vulnerability? We want to know.

Security contact: security@ab0t.com

For urgent issues, include "[URGENT]" in the subject line. We check this daily, and more often when we're heads down on a release.

Last updated: May 2026.