Entailment Labs

Security posture

Built by people who ship security products. Every control below carries its current status and the document that evidences it. Nothing is claimed as done before it is.

Section 1 — security posture

Status as of 2026-09-01. This page, the security pack and the vendor onboarding pack are generated from the same file.

The pack is a summary for procurement. Full policy texts and questionnaire answers follow a mutual NDA.

Certifications and registrations

CertificationStatusTarget
SOC 2 Type IInot startedplaceholder
ISO 27001not startedplaceholder
RegistrationStatus
Company registration (Private Limited, MCA)pending
GST registrationpending
Trademark, classes 42 and 9pending
Cyber insurancepending

Section 2 — certifications and registrations

SOC 2 Type II and ISO 27001 are not started. A 90-day readiness plan exists for SOC 2; the observation window follows it.

Company registration, GST, the trademark filing and cyber insurance are pending. Certificates are added to the vendor onboarding pack as each is issued.

What every contract says

TermWhat it means for your client
Breach notice within 72 hoursWe notify you within 72 hours of confirming an incident that affects your data.
No training on partner dataWe never train, fine-tune or evaluate models for anyone else on your documents. Model providers are engaged only under no-training terms.
Per-partner isolationOne environment, database, object store and credential set per partner. No route between partner environments.
Data residencyIndia, the EU or the US, chosen per SOW.
Sub-processor noticeA published list, and 30 days' advance notice before a change.
Deletion on exitWithin 30 days of exit, including backups, with a signed certificate.
TransferEverything we build transfers to you. Code, prompts, rules, evaluation sets and documentation.

Section 3 — the contract

These terms are in the data processing addendum, which covers GDPR Article 28 and the India DPDP Act 2023. Drafted; lawyer review pending.

We do not contact your clients. Ever.

Controls

Section 4 — controls. 22 controls as of 2026-09-01: 10 implemented, 10 planned, 2 not started. Evidence names the policy in the security pack.

ControlStatusEvidenceNote
Encryption in transitimplementedPolicy 03, encryptionTLS 1.2 or later on every connection, external and internal; TLS 1.0, 1.1, SSL and plaintext protocols refused; HSTS on web endpoints.
Encryption at restimplementedPolicy 03, encryptionAES-256 with provider-managed keys on every database, object store, queue and backup; on by default in every environment we build. Partner-managed keys are a placeholder option per SOW.
Per-partner isolationimplementedPolicy 01, information securityOne project or namespace, database, object store and credential set per partner; no route between partner environments; row-level security in the portal. Diagram in 02-security/architecture.md.
MFA for all staffimplementedPolicy 02, access controlEnforced on every system that supports it, for staff, contractors and partner portal users; app-based or hardware factors.
Least-privilege access with quarterly reviewplannedPolicy 02, access controlRoles are least-privilege by default and scoped per partner environment. The quarterly review cycle starts with the first partner environment; first review placeholder — Q1 2027.
Append-only audit loggingimplementedPolicy 04, logging and monitoringPer-partner audit log, written once with the provider's write-once setting; every portal action, review decision, export and model call is logged; extract available to the partner.
Backups and restore testsplannedPolicy 07, backup and recoveryManaged daily backups are on by default in every environment; the first documented restore test is placeholder — Q1 2027.
Incident response with 72-hour partner noticeplannedPolicy 05, incident responsePolicy, Sev 1 to 4 table and the 72-hour notice commitment are in place and mirrored in the DPA. The security@ mailbox goes live with the domain; the first tabletop exercise is placeholder — Q1 2027.
Vulnerability and dependency scanningplannedPolicy 08, secure developmentDependency alerts and secret scanning run in the repository; scheduled scanning of running infrastructure is selected with the SOC 2 tooling, placeholder — Q1 2027.
Secure SDLCimplementedPolicy 08, secure developmentVersion control, review before merge with branch protection, CI tests, pinned dependencies, no secrets in code, separate staging and production, change records.
AI model monitoring and driftimplementedPolicy 09, ai model monitoring and driftModel, prompt and schema versions pinned per partner; every change gated on the partner's evaluation set against the SOW accuracy floor; drift signals raise alerts and feed the review queue; rollback to the previous pinned version.
Human review queueimplementedPolicy 09, ai model monitoring and driftLow-confidence fields, failed validation and a random sample go to a person before delivery; every decision is written to the audit log with the reviewer's identity.
No training on partner dataimplementedPolicy 09, ai model monitoring and driftWe never train, fine-tune or evaluate models for another partner on partner data; model providers are engaged only under no-training terms. Mirrored in the DPA.
Data retention and deletion on exitimplementedPolicy 10, data retention and deletionRetention days are a per-partner setting in the portal, per data class; deletion within 30 days of exit, including backups, with a signed certificate. Mirrored in the DPA.
Sub-processor managementplannedPolicy 06, vendor managementApproval before use, DPA flow-down, published list and 30-day advance notice of change are policy. The vendor list is provisional until the cloud host and model provider are confirmed, placeholder — Q1 2027.
Business continuityplannedPolicy 12, business continuityPlan written; multi-zone managed services within the partner's region; everything we build transfers to the BPO. First continuity test placeholder — Q2 2027.
Penetration testplannedPolicy 08, secure developmentAnnual external test of the portal and partner APIs is required by policy 08. The first test is not yet commissioned; target placeholder — Q1 2027, before the first production partner.
SOC 2 Type IInot startedSOC 2 roadmapNot started as of 2026-09-01. A 90-day readiness plan exists; the Type II observation window follows it. Target placeholder.
ISO 27001not startedSOC 2 roadmapNot started as of 2026-09-01. Decision depends on partner demand in the EU and India; see the roadmap. Target placeholder.
Cyber insuranceplannedVendor onboarding packPending as of 2026-09-01. A certificate of insurance is added to the vendor onboarding pack once the policy is bound; limits placeholder.
Data residency options (India, EU, US)plannedPolicy 01, information securityRegion chosen per SOW; ap-south-1, eu-central-1 or us-east-1 at the cloud host, which is a placeholder to confirm.
Security awareness trainingplannedPolicy 11, acceptable useRequired on joining and annually by policy 11; first cycle placeholder — Q1 2027.

Sub-processors

NamePurposeRegionStatus
Cloud host — placeholder — confirmCompute, managed database, object storage, backups and key management for each partner environmentap-south-1 (India), eu-central-1 (EU) or us-east-1 (US), chosen per SOWplanned
LLM API provider — placeholder — confirmModel inference for extraction, classification and agents; no-training and no-retention terms requiredplaceholder — confirm per provider and SOWplanned
Transactional email provider — placeholder — confirmPortal notifications and alerts; no partner documents or audio in emailplaceholder — confirmplanned
Error monitoring — placeholder — confirmApplication error and performance telemetry; partner content scrubbed before sendplaceholder — confirmplanned

Section 5 — sub-processors

Every entry is provisional until the cloud host and the model provider are confirmed. Approval before use, DPA flow-down and 30 days’ notice of change are policy.

The sub-processor list as a page

Vulnerability disclosure

If you find a security problem in anything we run, write to security@entailmentlabs.com. Include what you found, where, how to reproduce it and how to reach you. We acknowledge every report, tell you what we did about it, and do not take action against good-faith research.

The same contact is published at /.well-known/security.txt. Security incidents that affect a partner’s data go to the same mailbox and are handled under the incident response policy, with notice to the partner within 72 hours of confirmation.

Requesting the security pack

  1. Email security@entailmentlabs.com with your company name, your role and the items you need.
  2. The policy index, the security pack, the architecture note and this page are sent without an NDA.
  3. Full policy texts, the questionnaire answers and evidence artefacts follow once the mutual NDA is signed.
  4. Your own questionnaire, in SIG, CAIQ or your own form, is answered from the same source answers.

Section 6 — disclosure

Acknowledgement time for reports: placeholder business days. Reward and safe-harbour terms: placeholder — replace once set.

The security@ mailbox goes live with the domain.

Bring us one process.
It comes back automated, monitored and under your name.

Request a pilot scope

We do not contact your clients. Ever.