Compliance
Actively pursuing SOC 2 Type II with Secureframe, which provides continuous monitoring of our controls across production systems.
Security commitment
We treat every camera feed, model weight, and customer artifact as confidential. Our controls are being formalized under SOC 2 Type II with Secureframe.
Actively pursuing SOC 2 Type II with Secureframe, which provides continuous monitoring of our controls across production systems.
TLS 1.2+ in transit. AES-256 at rest. Customer artifacts (footage, weights, eval sets) are logically isolated per tenant.
SSO + MFA for all internal access. Least-privilege IAM, short-lived credentials, and full audit logs on production systems.
Customer video is processed only for agreed purposes, with configurable retention. Anonymization (faces, plates) available at the edge.
Background checks, annual security training, acceptable-use and confidentiality agreements for every employee and contractor.
Documented runbook with named responders, escalation paths, and customer notification commitments.
Third-party processors are reviewed before onboarding and re-reviewed annually. Sub-processor list available on request.
Data processing agreements on request. EU-based infrastructure available for workloads that require it.
Engineering practices
Great security outcomes come from boring, repeatable practices applied consistently. These are ours.
Our SOC 2 audit report (once issued), Data Processing Agreement, and current sub-processor list are available under NDA on request. If your procurement team needs something specific, just ask — we’ll send the most recent version.
Security-related disclosures and concerns: security@ventral.ai
Procurement?
Reach out with your security questionnaire. We've filled out more than a few.