— Compliance

Audit-ready by design, not by accident.

cloud

SIEM-native telemetry

CIM-compliant JSON events land in Splunk, Sentinel, Elastic, Datadog with no glue code.

auto_awesome

Client-side PII interception

Intercept LLM prompts before egress to prevent leaks invisible to network DLP.

security

SOC 2 & ISO posture

Annual SOC 2 Type II and ISO 27001 attestations satisfy auditors and procurement teams.

A compliance certificate tells you what was true during an audit window. Our architecture is designed so the audit is never the whole story — zero payload retention and customer-managed keys protect you on the days between audits.

— Defog engineering

What certifications actually mean for your procurement team.

A compliance certificate tells you what was true during an audit window. Our architecture is designed so the audit is never the whole story — zero payload retention and customer-managed keys protect you on the days between audits.
— Defog engineering

Certifications & Frameworks

SOC 2 Type II

Created by the AICPA, SOC 2 evaluates your security controls across five Trust Service Criteria over a 12-month observation period. Type I checks that controls exist; Type II — Defog's standard — confirms they operated continuously. In a 2024 survey by Vanta, 84% of enterprise buyers required SOC 2 before signing a SaaS contract. Defog's audit is conducted annually by Coalfire, one of the largest specialist firms in the space. Report available to customers under NDA.

ISO 27001:2022

The international standard for information security management systems. The 2022 revision added 11 new controls addressing cloud security and threat intelligence — directly relevant to AI governance. 27001 is the required baseline for public sector contracts in the EU, UK, and Australia. Our certification covers the full Shield platform and corporate infrastructure. Surveillance audits annually; full re-certification every three years.

GDPR

In force since May 2018, GDPR non-compliance penalties can reach €20M or 4% of annual global revenue. Meta's 2023 fine of €1.2B for transferring EU data to US servers without safeguards set the benchmark for AI data governance enforcement. Defog's DPA is available pre-signature; EU data residency is a deployment option on Business+; zero payload retention means there is no personal data to request deletion of. We operate as a data processor under Article 28.

HIPAA

The Health Insurance Portability and Accountability Act (1996) governs PHI in the US. A BAA is required before any covered entity shares PHI with a vendor. In 2024, Change Healthcare's ransomware breach exposed data for 190M Americans and cost $2.45B. AI platforms that pass PHI to external LLMs without screening for 18 HIPAA identifiers first were a primary attack surface. Defog's PHI patterns ship by default on health-sector deployments. BAA on Enterprise+.

ISO 42001 — AI Management

Published December 2023, ISO 42001 is the first international standard specifically for AI management systems. It addresses AI risk, transparency, explainability, and human oversight — the exact governance framework that enterprises now require from AI vendors. We are in active audit with target Q2 completion. Customers with AI system procurement requirements can use our pre-audit evidence pack as interim documentation.

NIS 2 / DORA

NIS 2 (EU Network and Information Security Directive 2) expands cybersecurity obligations to 18 critical sectors including financial services, health, and cloud providers. DORA (Digital Operational Resilience Act) adds AI vendor risk requirements specifically for EU financial entities from January 2025. Both frameworks require supply chain security, incident reporting within 24 hours, and third-party risk management. Defog provides a vendor security questionnaire pre-completed for both frameworks.

— Certifications & frameworks
SOC 2
Type II audited annually by Coalfire · report under NDA
ISO 27001
27001:2022 certified · scope: full Shield platform + corporate
ISO 27701
Privacy management certified · pairs with 27001
ISO 42001
AI Management System · in audit (target Q2)
GDPR
DPA available pre-signature · EU data residency option
HIPAA
BAA on Enterprise+ · PHI patterns ship by default
PCI DSS
Service Provider Level 1 · AOC available
FedRAMP
Moderate (in progress) · IL4 roadmapped
CCPA / CPRA
Consumer rights honored across product
NIS 2 / DORA
EU operational-resilience aligned · attestation on request
— Security posture

Our audit and testing schedule.

— Audit cadence
SOC 2 Type II
Annual · 12-month observation window · Coalfire
ISO 27001 surveillance
Annual · Schellman
Pentest
Quarterly · external red team · rotating vendor pool (no vendor audits itself twice in a row). Full scope: API, extension, agent runtime, CI/CD pipeline. Critical findings disclosed to customers within 48 hours.
Vulnerability scans
Daily (production) · weekly (corporate)
Code review
Mandatory two-reviewer policy · SCA (software composition analysis) + SAST (static analysis) runs in every CI pipeline. No merge without a clean security scan. Branch protection enforced at the git host level, not just convention.
Tabletop exercises
Quarterly · cross-functional (security, engineering, legal, exec) · post-mortems published. Scenarios include: LLM prompt injection at scale, credential exfil via compromised extension, data residency violation by a sub-processor.

How your data is handled at every layer.

— Data handling
lock

Zero retention

Detected payloads never persist. Patterns live in C-heap, wiped after parse. Only OCSF-formatted event metadata leaves the agent.

gpp_good

Customer-controlled keys

BYOK on Enterprise+. Rotate, revoke, or hold keys in your own HSM. We can’t decrypt what you don’t let us.

stream

Audit-grade logs

Every policy decision — block, redact, allow — is logged immutably with hash-chained entries. Replayable for your auditor.

Sub-processors and your supply chain.

Every sub-processor we use has been evaluated against the same security criteria we hold ourselves to. If a sub-processor fails recertification, they are removed from production within 30 days.
— Defog security team
— Sub-processors
AWS
Primary infra · us-east-1, eu-west-1, ap-southeast-2 · ISO + SOC
Cloudflare
Edge + DDoS · ISO 27001 + SOC 2
Datadog
Internal observability (no customer data) · SOC 2
Auth0
Customer identity · SOC 2 · ISO 27001 · HIPAA
Stripe
Billing · PCI DSS Level 1
Notice cadence
Sub-processor list public · 30 days advance notice on changes

Need the SOC 2 report, ISO certificate, or DPA?

Trust portal request returns documents within one business day.

Request via trust portal