← Trust Portal

Security Pack

Prepared for security review. It covers where SecuriX runs, what data it touches, how long that data is kept, who else is involved, and what happens when something goes wrong.

Last reviewed: 2026-08-26

01 — Certification status

What We Hold, and What We Don't

Stated plainly and up front. SecuriX is an early-stage company and does not hold SOC 2 or ISO certification today. Where this site references those frameworks, it means the controls are designed against them — not that an audit has been completed.

Current status

SOC 2 Type II
Not held

Controls are designed against SOC 2 criteria. No audit has been completed and no report exists.

Google CASA
Audit in progress

Required for Google restricted OAuth scopes. Assessment underway; not yet complete.

ISO/IEC 27001
Not held

No certification. Referenced elsewhere on this site only as a framework we design against.

ISO/IEC 42001
Not held

AI management system standard. Under evaluation as a roadmap item.

GDPR / DPDP Act
DPA in preparation

We do not yet have a counsel-reviewed Data Processing Agreement. One is being prepared. In self-hosted and VPC deployments SecuriX processes no customer personal data, which narrows the scope considerably.

02 — Architecture & data flow

Where Requests Go

Two enforcement points. The LLM Gateway governs traffic to model providers; the Secure MCP Server governs what agents may do against your own systems. Both evaluate policy before data moves and again on the way back.

Client layer — inside your network
Employees
Chat portal via SSO
AI Agents & Apps
Programmatic callers
Public chatbots
Blocked at the network edge
SecuriX control plane — self-hosted, your VPC, or SecuriX Cloud
LLM Gateway
  • DLP policy engine — PII detected and redacted
  • Credential substitution — provider keys vaulted
  • Model whitelisting per team and role
  • Request / response streaming and logging
Secure MCP Server
  • OPA / Rego policy evaluated pre- and post-call
  • Agent over-reach prevention (e.g. recursive delete)
  • Tool-call conversion to provider REST APIs
  • Response redaction before the model sees data
External model providers
OpenAI · Anthropic · Azure OpenAI — redacted payloads only
Enterprise data layer
Your mail, files, tickets, and databases
03 — Deployment & residency

It Runs Where You Put It

Self-hosted

Your data centre. No SecuriX-operated subprocessor sits in the data path, and no prompt content leaves your network.

Private VPC

Your cloud tenancy, your key management, your network policy. Residency follows the region you deploy into.

SecuriX Cloud

Managed by us for evaluation. The subprocessor list below applies only to this model.

04 — Data handling & retention

What We Touch and Keep

Data handling

Request metadata
Recorded for every request

User identity, team, model, token counts, cost, policy decision, timestamp, and a cryptographic hash of the prompt. This is what powers cost attribution, budgets, and the audit trail.

Prompt and response content
Persisted only where DLP or policy flagged, redacted, or blocked the request

Traffic that passes policy cleanly has its metadata recorded but its content is not stored. You retain the material a compliance review needs without warehousing every employee conversation. In self-hosted and VPC deployments that store sits inside your own network.

Audit log retention
Configurable per deployment

Retention is set by the customer to match their own records policy. In self-hosted and VPC deployments the data never leaves your infrastructure, so deletion is under your control.

Redacted data
PII is redacted before egress to the model provider

DLP runs on the request before it leaves the gateway, and on tool responses before the model sees them.

Provider credentials
Encrypted at rest using envelope encryption

Data keys are wrapped by a KMS-held master key. Plaintext keys are never persisted.

Training on customer data
SecuriX does not train models on customer data

SecuriX operates no models of its own. Provider-side training terms are governed by the customer's own contract with OpenAI, Anthropic, or Azure.

Data residency
SecuriX Cloud: United States (Google Cloud Platform)

Applies to the managed offering only. Self-hosted and VPC deployments reside wherever you deploy them, so residency requirements are met by your own choice of region.

Encryption & key management

Envelope encryption
Per-record data keys wrapped by a KMS master key
Google Cloud KMS
Supported

Configured via GCP_KMS_KEY_PATH.

HashiCorp Vault
Supported

Customer-operated Vault — the master key never leaves your control.

Transport security
TLS 1.3

All traffic in transit, including calls onward to model providers.

05 — Subprocessors

Who Else Is Involved

These apply to SecuriX Cloud only. In self-hosted and VPC deployments there is no SecuriX-operated subprocessor in the data path. Model providers you connect are contracted directly by you, not by us.

SubprocessorPurposeData touched
Google Cloud Platform
Application hosting, managed database, key management, messagingApplication data, encrypted credentials, audit records
PostHog (US)
Product analytics on the marketing site and dashboardUsage telemetry and page events. No prompt content.
Neon (US region)
Managed PostgreSQLApplication data and audit records for flagged traffic
Formspree
Demo and contact form submissions on securix.appName, email, and message submitted through the marketing site. No product data.
  • Self-hosted deployments bundle PostgreSQL — Neon is not involved.
  • SecuriX sends no transactional email from the product. Formspree applies only to the marketing website.
  • Model providers you connect are contracted directly by you and are not SecuriX subprocessors.
06 — Incident response

When Something Goes Wrong

Response commitments

Security contact
security@securix.app

Reports are triaged during Indian Standard Time business hours. Report anything you believe to be a vulnerability — we will not pursue researchers acting in good faith.

Customer notification target
Within 48 hours of confirming a breach affecting your data

Ahead of the 72 hours required under GDPR Art. 33. Notification goes to your nominated security contact.

Post-incident review
Written root-cause analysis issued to affected customers

Sent by email once the immediate incident is contained, covering what happened, what data was involved, and what changed as a result.

Severity model

SEV-1

Confirmed unauthorised access to customer data, or a full outage of the gateway in production.

Triage begins immediately on detection. Customer notified within 48 hours of confirmation.

SEV-2

Vulnerability that could lead to data exposure, or degraded policy enforcement — for example DLP failing open.

Triage within one business day. Fix prioritised above all feature work.

SEV-3

Security defect with no immediate exposure — a dependency advisory, or a hardening gap.

Triage within three business days. Scheduled into the next release cycle.

SEV-4

Informational finding or recommended improvement.

Acknowledged and logged in the security backlog.

07 — Documents

Available for Review

Data Processing Agreement (DPA)

Not yet available. We will sign your standard DPA where its terms are ones we can meet, and we will tell you plainly where they are not.

In preparation
CAIQ Lite / SIG Lite response

Completed from this pack for your review. We will also complete your own questionnaire rather than asking you to accept ours.

On request
Enterprise architecture data sheet
Download

Questions From Your Security Team

We will complete your own questionnaire rather than asking you to accept ours, and we will answer “not yet” where that is the honest answer.

Talk to Us