Skip to content

Security, data residency and how your information is handled

Last updated

Safety data is the most sensitive operational information a company holds. It names people, records injuries, and creates evidence that outlives the incident. Here is exactly how we handle it.

Certification status

Held today In progress Planned
None. ASIP Technologies holds no third party security or management system certification at this date. SOC 2 Type II readiness. Automated internal control auditing runs daily against the SOC 2 control set, with evidence collected through read-only checks across our source control and cloud environment. A written security policy set, risk assessment, vendor register, incident response runbook and business continuity plan are in place. SOC 2 Type II audit, ISO 27001, ISO 9001. HIPAA alignment for regulated customer environments.

Last reviewed 31 July 2026. We update this page when the position changes rather than when it becomes convenient.

Two layers, never mixed

Your intelligence learns from your operation and only your operation, inside your own fenced environment. No other customer's records touch your system. Yours never touch theirs.

Your data is never used to train models serving another customer, under any circumstance, and this is enforced at the architecture level rather than by policy alone.

Where your data lives

US customer data is stored on US servers. Canadian, UK and EU customer data is held in region under local data protection law, including GDPR.

Deployment options for enterprise customers include your choice of major cloud region, with sovereign and on-premises arrangements available.

Isolation and access

Each customer runs in an isolated workspace. Access is scoped by role and by site. Every access is logged. Administrative access is audited and configurable to your just culture policy.

Retention and records

Records are retained to the standards your regulator requires, including 30 year retention for exposure records under 29 CFR 1910.1020 where applicable. Records are append-only where the standard demands an unbroken audit trail.

How AI touches your data

AI drafts, humans decide. Every output carries its evidence. No consequential action is released without a named approver. Model processing runs on infrastructure we own rather than metered third party services, which is why we can make that commitment.

Reporting a vulnerability

Send findings to [email protected]. We acknowledge within one business day and give you a remediation timeline within five.