Skip to content
EISBERG
Trust Center

Security posture, compliance, and the audit history.

Customer-owned data plane is the foundation. Everything else is built so a CISO, a regulator, or a board-level audit committee can verify what we claim — without needing to trust us.

Customer-owned data plane

Your data lives in your S3 / Azure Blob / GCS, behind your KMS keys — and the write path is fail-closed by design: when a bound customer key can't be honored, the platform refuses to write rather than write plaintext. Verified in our live environment, down to the key ARN on the objects.

Policy as code at every layer

Row-level, column-level, action-level, agent-level — enforced at one governed query chokepoint, on by default. Column masking and cross-tenant isolation are verified in our live environment, not asserted: viewers see masked values, foreign credentials are denied.

Tamper-evident audit trail

HMAC-chained audit trail of every query, every action, every agent decision — each event cryptographically bound to its predecessor, with chain-integrity verification exposed as a live API you can call during the audit.

Hard kill switches

Revoke any agent, any user, any workspace globally in one API call. Audit log records who, what, when, why.

Certifications

What we are pursuing and what is ready today.

We will never claim a certification we do not hold. Status below is current as of the date on this page.

SOC 2 Type II

In progress

Planned — on the certification roadmap

ISO 27001

In progress

Planned — on the certification roadmap

HIPAA BAA

In progress

BAA terms negotiable for design partners

FedRAMP Moderate

In progress

Planned — architecture designed for it

GDPR Article 28

In progress

DPA + EU SCCs available on request

Customer-key encryption

Ready

Fail-closed KMS on data + metadata — verified in our live environment

Sub-processors

Who else touches your environment.

Full sub-processor list available under NDA. We disclose every third-party service that interacts with customer environments, including their certifications and contractual data-processing terms.

We use a small number of sub-processors for cloud infrastructure (AWS, Azure, GCP for control-plane hosting), error monitoring, and operational telemetry. None of them store customer data — customer data lives only in the customer's own object storage.

Request the full list along with their contractual safeguards by emailing trust@eisbergdata.com.

Need the full security package?

CISO whitepaper, threat model, agent-governance specification, policy library, audit trail schema, and sub-processor list — all available under NDA.