Trust center

A security company should be boringly secure.

You're routing your most sensitive AI traffic through us. Here's exactly how we handle it.

SOC 2 Type IIISO 27001 · in auditGDPR & CCPAHIPAA BAA available

Zero-retention by default

Guard inspects requests in memory. Nothing is written to disk unless you enable Trace, and you can store hashes only.

Deploy where your data lives

Managed cloud in US or EU regions, your own VPC via Helm, or fully air-gapped on your hardware with offline licensing.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, customer-managed keys on Enterprise. Provider keys are stored in an HSM-backed vault.

No training on your traffic

Customer data never trains shared classifiers. Tenant-specific tuning stays inside your tenant and is deleted on request.

Least-privilege access

SSO, hardware keys and just-in-time access for all staff. Every production action is logged and reviewed.

Continuous testing

Annual third-party pentests, a public bug bounty, and Probe red-teaming Probe on every release.

Responsible disclosure

Found something? We'll pay you for it.

Report vulnerabilities to [email protected]. We acknowledge within 24 hours, keep you updated, and reward valid findings up to $15,000.

Report a vulnerabilityRequest our SOC 2 report
Sub-processors

Who touches what.

VendorPurposeRegionCustomer data
Amazon Web ServicesManaged cloud hostingUS · EUYes, encrypted
Google CloudSecondary region & backupsUS · EUYes, encrypted
DatadogInfrastructure metricsUSNo (metadata only)
StripeBillingUSNo
LinearSupport ticket trackingUSOnly what you send us