Security posture
Built by people who ship security products. Every control below carries its current status and the document that evidences it. Nothing is claimed as done before it is.
Section 1 — security posture
Status as of 2026-09-01. This page, the security pack and the vendor onboarding pack are generated from the same file.
The pack is a summary for procurement. Full policy texts and questionnaire answers follow a mutual NDA.
Certifications and registrations
| Certification | Status | Target |
|---|---|---|
| SOC 2 Type II | not started | placeholder |
| ISO 27001 | not started | placeholder |
| Registration | Status |
|---|---|
| Company registration (Private Limited, MCA) | pending |
| GST registration | pending |
| Trademark, classes 42 and 9 | pending |
| Cyber insurance | pending |
Section 2 — certifications and registrations
SOC 2 Type II and ISO 27001 are not started. A 90-day readiness plan exists for SOC 2; the observation window follows it.
Company registration, GST, the trademark filing and cyber insurance are pending. Certificates are added to the vendor onboarding pack as each is issued.
What every contract says
| Term | What it means for your client |
|---|---|
| Breach notice within 72 hours | We notify you within 72 hours of confirming an incident that affects your data. |
| No training on partner data | We never train, fine-tune or evaluate models for anyone else on your documents. Model providers are engaged only under no-training terms. |
| Per-partner isolation | One environment, database, object store and credential set per partner. No route between partner environments. |
| Data residency | India, the EU or the US, chosen per SOW. |
| Sub-processor notice | A published list, and 30 days' advance notice before a change. |
| Deletion on exit | Within 30 days of exit, including backups, with a signed certificate. |
| Transfer | Everything we build transfers to you. Code, prompts, rules, evaluation sets and documentation. |
Section 3 — the contract
These terms are in the data processing addendum, which covers GDPR Article 28 and the India DPDP Act 2023. Drafted; lawyer review pending.
We do not contact your clients. Ever.
Controls
Section 4 — controls. 22 controls as of 2026-09-01: 10 implemented, 10 planned, 2 not started. Evidence names the policy in the security pack.
| Control | Status | Evidence | Note |
|---|---|---|---|
| Encryption in transit | implemented | Policy 03, encryption | TLS 1.2 or later on every connection, external and internal; TLS 1.0, 1.1, SSL and plaintext protocols refused; HSTS on web endpoints. |
| Encryption at rest | implemented | Policy 03, encryption | AES-256 with provider-managed keys on every database, object store, queue and backup; on by default in every environment we build. Partner-managed keys are a placeholder option per SOW. |
| Per-partner isolation | implemented | Policy 01, information security | One project or namespace, database, object store and credential set per partner; no route between partner environments; row-level security in the portal. Diagram in 02-security/architecture.md. |
| MFA for all staff | implemented | Policy 02, access control | Enforced on every system that supports it, for staff, contractors and partner portal users; app-based or hardware factors. |
| Least-privilege access with quarterly review | planned | Policy 02, access control | Roles are least-privilege by default and scoped per partner environment. The quarterly review cycle starts with the first partner environment; first review placeholder — Q1 2027. |
| Append-only audit logging | implemented | Policy 04, logging and monitoring | Per-partner audit log, written once with the provider's write-once setting; every portal action, review decision, export and model call is logged; extract available to the partner. |
| Backups and restore tests | planned | Policy 07, backup and recovery | Managed daily backups are on by default in every environment; the first documented restore test is placeholder — Q1 2027. |
| Incident response with 72-hour partner notice | planned | Policy 05, incident response | Policy, Sev 1 to 4 table and the 72-hour notice commitment are in place and mirrored in the DPA. The security@ mailbox goes live with the domain; the first tabletop exercise is placeholder — Q1 2027. |
| Vulnerability and dependency scanning | planned | Policy 08, secure development | Dependency alerts and secret scanning run in the repository; scheduled scanning of running infrastructure is selected with the SOC 2 tooling, placeholder — Q1 2027. |
| Secure SDLC | implemented | Policy 08, secure development | Version control, review before merge with branch protection, CI tests, pinned dependencies, no secrets in code, separate staging and production, change records. |
| AI model monitoring and drift | implemented | Policy 09, ai model monitoring and drift | Model, prompt and schema versions pinned per partner; every change gated on the partner's evaluation set against the SOW accuracy floor; drift signals raise alerts and feed the review queue; rollback to the previous pinned version. |
| Human review queue | implemented | Policy 09, ai model monitoring and drift | Low-confidence fields, failed validation and a random sample go to a person before delivery; every decision is written to the audit log with the reviewer's identity. |
| No training on partner data | implemented | Policy 09, ai model monitoring and drift | We never train, fine-tune or evaluate models for another partner on partner data; model providers are engaged only under no-training terms. Mirrored in the DPA. |
| Data retention and deletion on exit | implemented | Policy 10, data retention and deletion | Retention days are a per-partner setting in the portal, per data class; deletion within 30 days of exit, including backups, with a signed certificate. Mirrored in the DPA. |
| Sub-processor management | planned | Policy 06, vendor management | Approval before use, DPA flow-down, published list and 30-day advance notice of change are policy. The vendor list is provisional until the cloud host and model provider are confirmed, placeholder — Q1 2027. |
| Business continuity | planned | Policy 12, business continuity | Plan written; multi-zone managed services within the partner's region; everything we build transfers to the BPO. First continuity test placeholder — Q2 2027. |
| Penetration test | planned | Policy 08, secure development | Annual external test of the portal and partner APIs is required by policy 08. The first test is not yet commissioned; target placeholder — Q1 2027, before the first production partner. |
| SOC 2 Type II | not started | SOC 2 roadmap | Not started as of 2026-09-01. A 90-day readiness plan exists; the Type II observation window follows it. Target placeholder. |
| ISO 27001 | not started | SOC 2 roadmap | Not started as of 2026-09-01. Decision depends on partner demand in the EU and India; see the roadmap. Target placeholder. |
| Cyber insurance | planned | Vendor onboarding pack | Pending as of 2026-09-01. A certificate of insurance is added to the vendor onboarding pack once the policy is bound; limits placeholder. |
| Data residency options (India, EU, US) | planned | Policy 01, information security | Region chosen per SOW; ap-south-1, eu-central-1 or us-east-1 at the cloud host, which is a placeholder to confirm. |
| Security awareness training | planned | Policy 11, acceptable use | Required on joining and annually by policy 11; first cycle placeholder — Q1 2027. |
Sub-processors
| Name | Purpose | Region | Status |
|---|---|---|---|
| Cloud host — placeholder — confirm | Compute, managed database, object storage, backups and key management for each partner environment | ap-south-1 (India), eu-central-1 (EU) or us-east-1 (US), chosen per SOW | planned |
| LLM API provider — placeholder — confirm | Model inference for extraction, classification and agents; no-training and no-retention terms required | placeholder — confirm per provider and SOW | planned |
| Transactional email provider — placeholder — confirm | Portal notifications and alerts; no partner documents or audio in email | placeholder — confirm | planned |
| Error monitoring — placeholder — confirm | Application error and performance telemetry; partner content scrubbed before send | placeholder — confirm | planned |
Section 5 — sub-processors
Every entry is provisional until the cloud host and the model provider are confirmed. Approval before use, DPA flow-down and 30 days’ notice of change are policy.
Vulnerability disclosure
If you find a security problem in anything we run, write to security@entailmentlabs.com. Include what you found, where, how to reproduce it and how to reach you. We acknowledge every report, tell you what we did about it, and do not take action against good-faith research.
The same contact is published at /.well-known/security.txt. Security incidents that affect a partner’s data go to the same mailbox and are handled under the incident response policy, with notice to the partner within 72 hours of confirmation.
Requesting the security pack
- Email security@entailmentlabs.com with your company name, your role and the items you need.
- The policy index, the security pack, the architecture note and this page are sent without an NDA.
- Full policy texts, the questionnaire answers and evidence artefacts follow once the mutual NDA is signed.
- Your own questionnaire, in SIG, CAIQ or your own form, is answered from the same source answers.
Section 6 — disclosure
Acknowledgement time for reports: placeholder business days. Reward and safe-harbour terms: placeholder — replace once set.
The security@ mailbox goes live with the domain.