Audit-ready by design, not by accident.
SIEM-native telemetry
CIM-compliant JSON events land in Splunk, Sentinel, Elastic, Datadog with no glue code.
Client-side PII interception
Intercept LLM prompts before egress to prevent leaks invisible to network DLP.
SOC 2 & ISO posture
Annual SOC 2 Type II and ISO 27001 attestations satisfy auditors and procurement teams.
A compliance certificate tells you what was true during an audit window. Our architecture is designed so the audit is never the whole story — zero payload retention and customer-managed keys protect you on the days between audits.
— Defog engineering
What certifications actually mean for your procurement team.
A compliance certificate tells you what was true during an audit window. Our architecture is designed so the audit is never the whole story — zero payload retention and customer-managed keys protect you on the days between audits.
Certifications & Frameworks
SOC 2 Type II
Created by the AICPA, SOC 2 evaluates your security controls across five Trust Service Criteria over a 12-month observation period. Type I checks that controls exist; Type II — Defog's standard — confirms they operated continuously. In a 2024 survey by Vanta, 84% of enterprise buyers required SOC 2 before signing a SaaS contract. Defog's audit is conducted annually by Coalfire, one of the largest specialist firms in the space. Report available to customers under NDA.
ISO 27001:2022
The international standard for information security management systems. The 2022 revision added 11 new controls addressing cloud security and threat intelligence — directly relevant to AI governance. 27001 is the required baseline for public sector contracts in the EU, UK, and Australia. Our certification covers the full Shield platform and corporate infrastructure. Surveillance audits annually; full re-certification every three years.
GDPR
In force since May 2018, GDPR non-compliance penalties can reach €20M or 4% of annual global revenue. Meta's 2023 fine of €1.2B for transferring EU data to US servers without safeguards set the benchmark for AI data governance enforcement. Defog's DPA is available pre-signature; EU data residency is a deployment option on Business+; zero payload retention means there is no personal data to request deletion of. We operate as a data processor under Article 28.
HIPAA
The Health Insurance Portability and Accountability Act (1996) governs PHI in the US. A BAA is required before any covered entity shares PHI with a vendor. In 2024, Change Healthcare's ransomware breach exposed data for 190M Americans and cost $2.45B. AI platforms that pass PHI to external LLMs without screening for 18 HIPAA identifiers first were a primary attack surface. Defog's PHI patterns ship by default on health-sector deployments. BAA on Enterprise+.
ISO 42001 — AI Management
Published December 2023, ISO 42001 is the first international standard specifically for AI management systems. It addresses AI risk, transparency, explainability, and human oversight — the exact governance framework that enterprises now require from AI vendors. We are in active audit with target Q2 completion. Customers with AI system procurement requirements can use our pre-audit evidence pack as interim documentation.
NIS 2 / DORA
NIS 2 (EU Network and Information Security Directive 2) expands cybersecurity obligations to 18 critical sectors including financial services, health, and cloud providers. DORA (Digital Operational Resilience Act) adds AI vendor risk requirements specifically for EU financial entities from January 2025. Both frameworks require supply chain security, incident reporting within 24 hours, and third-party risk management. Defog provides a vendor security questionnaire pre-completed for both frameworks.
- SOC 2
- Type II audited annually by Coalfire · report under NDA
- ISO 27001
- 27001:2022 certified · scope: full Shield platform + corporate
- ISO 27701
- Privacy management certified · pairs with 27001
- ISO 42001
- AI Management System · in audit (target Q2)
- GDPR
- DPA available pre-signature · EU data residency option
- HIPAA
- BAA on Enterprise+ · PHI patterns ship by default
- PCI DSS
- Service Provider Level 1 · AOC available
- FedRAMP
- Moderate (in progress) · IL4 roadmapped
- CCPA / CPRA
- Consumer rights honored across product
- NIS 2 / DORA
- EU operational-resilience aligned · attestation on request
- AES-256-GCM at rest · TLS 1.3 in transit · keys in HSM (FIPS 140-2 Level 3)
- Customer-managed keys (BYOK) on Enterprise+ via AWS KMS, GCP KMS, Azure Key Vault, Thales
- Quarterly third-party pentest by NCC Group · public summary, raw report under NDA
- Bug bounty via HackerOne · public scope · 24-hour triage SLA
- Zero retention of detected payloads — patterns wiped from C-heap after parse
- Hardware-bound device identity (TPM 2.0 / Secure Enclave attestation)
- EU + US + AU data residency · pin-to-region available
- Annual disaster-recovery exercise · quarterly tabletop · public RTO/RPO
Our audit and testing schedule.
- SOC 2 Type II
- Annual · 12-month observation window · Coalfire
- ISO 27001 surveillance
- Annual · Schellman
- Pentest
- Quarterly · external red team · rotating vendor pool (no vendor audits itself twice in a row). Full scope: API, extension, agent runtime, CI/CD pipeline. Critical findings disclosed to customers within 48 hours.
- Vulnerability scans
- Daily (production) · weekly (corporate)
- Code review
- Mandatory two-reviewer policy · SCA (software composition analysis) + SAST (static analysis) runs in every CI pipeline. No merge without a clean security scan. Branch protection enforced at the git host level, not just convention.
- Tabletop exercises
- Quarterly · cross-functional (security, engineering, legal, exec) · post-mortems published. Scenarios include: LLM prompt injection at scale, credential exfil via compromised extension, data residency violation by a sub-processor.
How your data is handled at every layer.
Zero retention
Detected payloads never persist. Patterns live in C-heap, wiped after parse. Only OCSF-formatted event metadata leaves the agent.
Customer-controlled keys
BYOK on Enterprise+. Rotate, revoke, or hold keys in your own HSM. We can’t decrypt what you don’t let us.
Audit-grade logs
Every policy decision — block, redact, allow — is logged immutably with hash-chained entries. Replayable for your auditor.
Sub-processors and your supply chain.
Every sub-processor we use has been evaluated against the same security criteria we hold ourselves to. If a sub-processor fails recertification, they are removed from production within 30 days.
- AWS
- Primary infra · us-east-1, eu-west-1, ap-southeast-2 · ISO + SOC
- Cloudflare
- Edge + DDoS · ISO 27001 + SOC 2
- Datadog
- Internal observability (no customer data) · SOC 2
- Auth0
- Customer identity · SOC 2 · ISO 27001 · HIPAA
- Stripe
- Billing · PCI DSS Level 1
- Notice cadence
- Sub-processor list public · 30 days advance notice on changes
Need the SOC 2 report, ISO certificate, or DPA?
Trust portal request returns documents within one business day.