Security

Your privacy,
our priority.

Enterprise-grade protection, full data sovereignty, transparent compliance and thoughtful governance. Built into every layer of Inferana.

Learn more in our trust center

Audits and Certifications

Certified for top‑tier data protection and governance.

ISO27001

ISO 27001: Certified to the global standard for information management.

AICPASOC 2

SOC2 Type II: Independently audited to ensure secure, reliable data handling.

GDPR

GDPR: Fully aligned with GDPR for strong data privacy and user protection.

Shield

No model training: Your data stays private and is never used to train AI models.

Deployment

Flexible deployment options, all compliant with the strictest security requirements

Multi-tenant SaaS: Hosted via Microsoft Azure on servers inside the EU.

Standard

Single tenant SaaS: Dedicated deployment managed by Inferana.

Enterprise(from 2,000+ seats)
aws
G

Bring your own cloud: Dedicated deployment in your own cloud.

Enterprise(from 5,000+ seats)
On-premise

On-premise: Hosting on custom Kubernetes setups via Helm charts.

Enterprise(from 5,000+ seats)

Trusted data foundations

EU hosting: The application and most models (configurable) are hosted entirely in the EU.

No training on customer data: Customer data is never used to train or improve AI models.

Encryption in transit and at rest: Data is encrypted using AES‑256 and TLS 1.2+.

Security architecture

Least‑privilege access: Access to data is limited to essential personnel only.

Defense‑in‑depth: Multiple layers of controls protect data across the platform.

Continuous refinement: Security controls are regularly updated to match evolving threats.

Hardened processing: Secure procedures govern data handling end‑to‑end.

Compliance and assurance

ISO 27001 certified: Inferana maintains certified information‑security controls.

SOC 2 Type II audited: Independent audits validate operational security.

GDPR compliant: Customers can exercise data rights and rely on consistent protection.

Independent penetration testing: Frequent independent third‑party penetration testing validates Inferana's security posture.

Vendor and sub-processor reviews: Inferana regularly evaluates sub-processors for compliance and data‑handling standards.

Model usage and BYOK

Bring your own API keys: Use your own model provider keys for supported LLMs.

Unified API: Access multiple model providers through a single interface.

Governance and admin controls

Workspace‑level permissions: Admins manage settings and access across the organization.

Mirrored access permissions: Inferana reflects source‑tool permissions in integrations 1:1 for consistency.

Optional analytics: Usage analytics can be enabled or disabled at the workspace level.

Vendor transparency: Subprocessors are reviewed and published for visibility.

Built‑in monitoring: Monitoring systems help detect potential security threats.

Legal documents

Privacy policyView document
Data protection addendum (DPA)View document
Terms & conditionsView document

FAQ