SecuritAI is built by a cybersecurity team, so security and privacy are the foundation, not features bolted on. This is exactly how we protect your data, where it lives, and the standards we align to.

Keep AI traffic and logs in Canada.
Your prompts and responses are never used to train any model.
In transit and at rest.
Full, exportable records of every request and block.
Role-based access, tenant isolation, API-key scoping.
Managed (Canada), private-VPC, or on-prem / air-gapped.
Aligned to the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications, CCCS guidance, and PIPEDA; aligned to NIST AI RMF and ISO/IEC 42001.
We state alignment and capability, not certifications we don’t yet hold. SOC 2 and formal certifications will be listed here when achieved.
Every prompt and response that passes through SecuritAI is inspected in memory and logged to your tenant. Your data is never used to train any model, never sold, and never shared between tenants. Logs are encrypted, retention is configurable by plan, and you can export or delete them at any time. For Canadian customers, traffic and logs stay within Canadian data residency.
SecuritAI relies on a small set of infrastructure sub-processors for hosting and email. The current list, with their purpose and region, is available on request as part of the Security Overview, and we notify customers before adding a new sub-processor that handles customer data.
Security researchers: found something? Report it to [email protected]. We respond quickly and credit responsible disclosures.
No. Your prompts and responses are never used to train any model, never sold, and never shared between tenants. They are inspected in real time and logged only to your own tenant.
For Canadian customers, SecuritAI keeps AI traffic and logs within Canadian data residency. Private-VPC and on-premises deployments let you keep all data inside your own environment.
Yes. SecuritAI offers managed hosting in Canada, deployment into your own private VPC, and fully on-premises or air-gapped installation for government and critical infrastructure.
SecuritAI is aligned to the NIST AI Risk Management Framework, the OWASP LLM Top 10, CCCS guidance, and PIPEDA. We state alignment and capability honestly and do not claim certifications we do not yet hold. SOC 2 and formal certifications will be listed here when achieved.
SecuritAI keeps a full, exportable audit log of every prompt, response, and block decision, encrypted at rest. Retention is configurable by plan, and the log is suitable for incident reporting and regulatory review under frameworks like Bill C-8.