Security
Enterprise-grade protection, full data sovereignty, transparent compliance and thoughtful governance. Built into every layer of Inferana.
Learn more in our trust center
Audits and Certifications
ISO 27001: Certified to the global standard for information management.
SOC2 Type II: Independently audited to ensure secure, reliable data handling.
GDPR: Fully aligned with GDPR for strong data privacy and user protection.
No model training: Your data stays private and is never used to train AI models.
Deployment
Multi-tenant SaaS: Hosted via Microsoft Azure on servers inside the EU.
Single tenant SaaS: Dedicated deployment managed by Inferana.
Bring your own cloud: Dedicated deployment in your own cloud.
On-premise: Hosting on custom Kubernetes setups via Helm charts.
EU hosting: The application and most models (configurable) are hosted entirely in the EU.
No training on customer data: Customer data is never used to train or improve AI models.
Encryption in transit and at rest: Data is encrypted using AES‑256 and TLS 1.2+.
Least‑privilege access: Access to data is limited to essential personnel only.
Defense‑in‑depth: Multiple layers of controls protect data across the platform.
Continuous refinement: Security controls are regularly updated to match evolving threats.
Hardened processing: Secure procedures govern data handling end‑to‑end.
ISO 27001 certified: Inferana maintains certified information‑security controls.
SOC 2 Type II audited: Independent audits validate operational security.
GDPR compliant: Customers can exercise data rights and rely on consistent protection.
Independent penetration testing: Frequent independent third‑party penetration testing validates Inferana's security posture.
Vendor and sub-processor reviews: Inferana regularly evaluates sub-processors for compliance and data‑handling standards.
Bring your own API keys: Use your own model provider keys for supported LLMs.
Unified API: Access multiple model providers through a single interface.
Workspace‑level permissions: Admins manage settings and access across the organization.
Mirrored access permissions: Inferana reflects source‑tool permissions in integrations 1:1 for consistency.
Optional analytics: Usage analytics can be enabled or disabled at the workspace level.
Vendor transparency: Subprocessors are reviewed and published for visibility.
Built‑in monitoring: Monitoring systems help detect potential security threats.