Skip to main content
Infravox AI
Book Demo
All systems operational

Trust & Security

Infravox is built for enterprises that take security seriously. Here is how we protect your infrastructure data, credentials, and privacy.

AES-256 EncryptionTLS 1.3 in transitSOC 2 in progressGDPR compliantRBAC enforced
Compliance

Compliance & Certifications

Our current compliance posture and roadmap.

SOC 2 Type II

In Progress

Security, availability, confidentiality controls audit — completion Q3 2026.

GDPR

Compliant

Data processing agreements available. EU data residency option available on Enterprise.

HIPAA

Enterprise

BAA (Business Associate Agreement) available for healthcare customers on Enterprise plan.

PCI DSS

Enterprise

PCI DSS scope reduction guidance and audit-ready evidence packages available.

ISO 27001

Roadmap

ISO 27001 certification planned for Q4 2026 following SOC 2 completion.

CIS Benchmarks

Built-in

CIS Benchmark scanning built into the Security Agent. Automated compliance reports.

Defense in depth

Security Controls

The technical and operational controls protecting your data.

Encryption at Rest

All customer data encrypted with AES-256. Encryption keys managed via AWS KMS with automatic rotation.

Encryption in Transit

TLS 1.3 enforced on all endpoints. HSTS enabled. Certificate pinning for mobile clients.

Credential Security

Cloud credentials stored in HashiCorp Vault with per-customer encryption. Never logged or exposed in UI.

Infrastructure Isolation

Each customer's data is logically isolated. Enterprise customers get dedicated VPC options.

Audit Logging

Every action taken by Infravox AI agents is logged with full audit trail. Immutable logs retained per plan.

Access Control

RBAC with least-privilege principles. SSO enforced for all Infravox employees. MFA required.

Penetration Testing

Regular third-party penetration tests. Bug bounty program in place. Responsible disclosure policy.

Uptime & Reliability

99.9% uptime SLA on Unlimited plan. 99.99% on Enterprise. Status page available at status.infravox.ai.

Incident Response

24/7 security monitoring. Defined incident response plan. Customer notification within 72 hours of any breach.

Responsible Disclosure

If you discover a security vulnerability in Infravox, please report it responsibly. We commit to acknowledging your report within 24 hours, keeping you informed of progress, and recognizing your contribution once resolved.

Report a vulnerability

Security questions?

Contact our security team directly for any questions about our practices.

Enterprise ready

Talk to us about security

Need a security review, DPA, BAA, or a walkthrough of our compliance posture? Our team will get you every answer you need.