Trust Center
Safe with your data. Up when you need it.
The controls behind the product: how your data is isolated, encrypted, and accessed, how we keep the service running, and where every claim on this page is written down in full.
99.9%
uptime target for the platform
AES-256
encryption at rest, TLS 1.2+ in transit
Per-tenant
logical isolation of customer data
24h
target acknowledgement on security reports
How we keep that promise
Your data stays yours
Customer data is logically isolated per tenant, and we don't train general-purpose models on it without your consent.
Encrypted end to end
TLS 1.2 or higher in transit, AES-256 or equivalent at rest, with keys managed through our cloud providers' key-management services.
Least-privilege access
Production access is restricted, logged, and reviewed. SSO and MFA internally; role-based access controls inside the product.
Built to stay up
Segmented infrastructure with monitoring and alerting on anomalous activity, plus backups and recovery procedures we test periodically.
Reviewed continuously
Peer code review, automated dependency and vulnerability scanning, and regular third-party penetration testing.
People, not just systems
Background checks where permitted by law, mandatory security and privacy training, and confidentiality obligations for all staff.
- SOC 2 Type II, in progress
- ISO/IEC 27001, in progress
- GDPR and CCPA, in progress
Security documentation is available to customers under NDA: ask your contact, or write to security@simplifyingai.com.
The same models,inside your own account
On the managed service, model calls go to each vendor's API. On an enterprise deployment they don't leave your cloud: ChatPlotDB runs in your AWS account and serves those same foundation models through Amazon Bedrock, in the region you choose.
Your account, your region
The agent runs inside your own AWS account and VPC, and Bedrock serves the models from the region you pick, so your prompts, your schema and your rows stay inside the boundary you already govern.
No third-party model API
Nothing is sent to Anthropic, OpenAI or anyone else, and nothing is used to train a shared or public model. The vendor keys the managed service needs simply aren't in the picture.
Governed like the rest of AWS
IAM roles, VPC isolation, KMS-managed keys and CloudTrail audit logs: model access is controlled by the same policies that already secure your infrastructure.
