TRUST CENTER

Security You Can Verify. Anonymity We Can Prove.

Everything your security, privacy and vendor-risk teams need to evaluate XPOSER.AI — encryption, data residency, our zero-knowledge anonymity architecture and AI governance, in one place.

Security posture
Live compliance status
SOC 2 Type I — audit in progress
2026
ISO 27001 — gap assessment
UNDERWAY
Penetration test — independent
COMPLETE
Data encrypted in transit & at rest100%
TLS 1.3
In transit
Certifications & Audits

Checked Independently.

We are committed to maintaining the highest standards of security and privacy. Check out our certifications and audits below.

In progress

SOC 2 Type I

Audit in progress with [AUDITOR NAME]; report expected [MONTH 2026]. Type II observation window follows immediately after.

Underway

ISO 27001

Gap assessment underway against the current standard, covering our information security management system end to end.

Completed

Penetration Test

Independent penetration test completed [DATE]. Executive summary available under NDA on request from your security team.

Data Protection

Your Data.
Your Region.

Encryption, isolation and residency are configured before you go live. You choose where your reports live.

Encrypted End To End
TLS 1.3 in transit, AES-256 at rest. No plaintext report ever touches disk.
Logical Tenant Isolation
Every customer's data is isolated per tenant. No shared report stores, ever.
Regional Hosting
Saudi Arabia, the United States, Canada and the EU. Your data resides in the region you choose.
Zero-Knowledge Follow-Up
Two-way follow-up runs through a channel even XPOSER.AI administrators cannot link to an identity.
Anonymity Architecture
1
Reporter speaks
Any language · any device
2
Transcript only
No voiceprint stored · no voice matching performed
3
Identity severed
Report is delivered with no link back to the reporter
4
Zero-knowledge follow-up
Your team can ask questions without ever learning who asked
Voiceprints retained
None — by design
Browse our resources →
AI Governance

AI Recommends.
Humans Decide.

Every classification is explainable, cited and reviewable — and we don’t use your data to train models for anyone else.

Policy citations on every decision
No cross-customer model training
Immutable audit log
Decision trail
Report classified against your policy set
AI
Policy clauses cited alongside the reasoning
AI
Severity proposed, never auto-actioned
AI
Your reviewer confirms or overrides
HUMAN
Decision written to the immutable audit log
LOGGED
Customer data used to train models for others
Never
Compliance Alignment

Everything The Auditors Ask About.

EU Whistleblower Directive
SOX
GDPR
Saudi PDPL
SAMA Whistle Blowing Policy
HIPAA (BAA available)
Quebec Law 25
Subprocessors

Every Vendor In The Chain.

Cloud and AI vendors engaged per hosting region.

Subprocessor US/Canada Europe KSA UAE Asia
Grok STT
ElevenLabs TTS
Gemini LLM
Grok Fallback LLM
Cloudflare R2
MongoDB Atlas
LlamaParser
LiveKit
Firebase
LangSmith
Pinecone
MS Graph API
Vendor Review

Send Us Your Questionnaire

Security reviews, DPAs, BAAs and penetration test summaries — our team turns them around directly.