SoxAIDocs
Security

Compliance

Regulatory compliance, certifications, and security standards

Compliance

Current Status

SoxAI is in the process of obtaining formal certifications. The following reflects our current compliance posture.

StandardStatusNotes
OWASP Top 10ImplementedFull mitigation of all Top 10 categories
SOC 2 Type IIIn ProgressTarget: Q3 2026
ISO 27001PlannedTarget: Q4 2026
GDPRCompliantEU data processing agreements available
CCPACompliantCalifornia consumer rights honored
HIPAANot certifiedContact us for Enterprise discussions

OWASP Top 10 Coverage

OWASP CategorySoxAI Implementation
A01 Broken Access ControlTenant isolation via tenant_id in all queries + PG Row-Level Security
A02 Cryptographic FailuresAES-256-GCM for secrets, Argon2id for passwords, TLS 1.2+ enforced
A03 InjectionAll DB queries via sqlc parameterized queries, no string concatenation
A04 Insecure DesignPre-consumption billing prevents overspend, scope-limited tokens
A05 Security MisconfigurationSecrets via Ansible Vault, internal services not exposed to internet
A06 Vulnerable Componentsgovulncheck and trivy scan every CI build
A07 Authentication FailuresBrute-force lockout, JWT rotation, WebAuthn MFA
A08 Software and Data IntegritySigned Docker images, dependency checksums
A09 Logging and MonitoringAudit log for all auth events, OTel traces for all requests
A10 SSRFUpstream URL validated against allowlist before every request

GDPR

SoxAI processes personal data as both a data controller (for account data) and data processor (when your prompts are forwarded to AI providers).

For EU customers:

  • Data Processing Agreements (DPA) are available on request
  • The right to access, rectify, and erase personal data is supported via the Console
  • Data is processed on the basis of contract performance and legitimate interests

Contact [email protected] to request a DPA.

Security Audits

SoxAI conducts internal security reviews before each major release. External penetration testing is planned for Q2 2026.

Audit reports are available to Enterprise customers under NDA.

Responsible Disclosure

We run a responsible disclosure program. If you discover a security vulnerability:

  1. Email [email protected] with details
  2. We acknowledge within 24 hours
  3. We provide a fix timeline within 72 hours for critical issues
  4. We credit researchers in our security changelog (with permission)

We do not take legal action against researchers acting in good faith.

Access Control Policy

SoxAI employees:

  • Access production systems only through a bastion host with MFA
  • Follow least-privilege principles (read-only access by default)
  • Cannot access prompt content — only metadata and token counts
  • Are subject to background checks

Production database credentials are managed via Ansible Vault and rotated quarterly.

Incident Response

In the event of a security incident:

  1. We contain and assess the incident within 4 hours
  2. We notify affected customers within 72 hours (as required by GDPR)
  3. We publish a post-mortem within 7 days

For critical infrastructure incidents, subscribe to status updates at status.soxai.io.