30 controls, by domain
Single-source-of-truth for procurement, legal, and infosec stakeholders evaluating SLAtech. Each control is marked Implemented (live now), Enterprise tier (live for the Enterprise contract shape), or Target quarter (scheduled, transparent date). Report vulnerabilities to security@slatech.ai.
5 controls
| Control | Status |
|---|---|
| GDPR — DSR portal, DPA on request, SCC 2021/914 for sub-processor transfers | Implemented |
| HIPAA — BAA-eligible single-tenant deployment | Enterprise tier |
| SOC 2 Type I report | Q3 2026 target |
| SOC 2 Type II report | Q2 2027 target |
| ISO 27001 certification | Q4 2026 target |
5 controls
| Control | Status |
|---|---|
| AES-256-GCM at rest, TLS 1.2+ in transit | Implemented |
| Multi-tenant logical isolation across all stores (SQL + vector search + blob) | Implemented |
| PII tokenisation / redaction before AI sub-processors (opt-in uploads + visitor messages) | Implemented |
| Hosting in your own jurisdiction available on request (Enterprise deployments) | Implemented |
| Customer data excluded from model training pipeline (contractual + technical) | Implemented |
4 controls
| Control | Status |
|---|---|
| Argon2id password hashing, configurable per-tenant password policy | Implemented |
| SAML SSO integration | Enterprise tier |
| Role-based access control (RBAC) with per-tenant roles | Implemented |
| Audit log of admin actions (login, role change, data export) | Implemented |
4 controls
| Control | Status |
|---|---|
| TLS 1.2+ enforced on every endpoint; HSTS preload | Implemented |
| Cloudflare WAF in front of every host | Implemented |
| Per-tenant API rate limiting (60-6000 RPM by tier) | Implemented |
| DDoS mitigation via Cloudflare upstream | Implemented |
4 controls
| Control | Status |
|---|---|
| Sentry — every backend service emits structured errors with PII scrubbing | Implemented |
| Per-tenant audit log export | Enterprise tier |
| Real-time uptime dashboard (status.slatech.ai) | Implemented |
| Synthetic transaction monitoring (5-minute cadence) | Implemented |
4 controls
| Control | Status |
|---|---|
| GitOps deploy pipeline (audited via GitHub Actions) | Implemented |
| Pre-deploy smoke tests + post-deploy QA harness | Implemented |
| Database backups (daily, 35-day retention) | Implemented |
| Point-in-time recovery (last 24 hours) | Implemented |
4 controls
| Control | Status |
|---|---|
| Dependabot — automated dependency updates on production branch | Implemented |
| GitHub CodeQL static analysis on every PR | Implemented |
| External penetration test (annual) | Q4 2026 target |
| Coordinated vulnerability disclosure policy | Published below |
Coordinated vulnerability disclosure
Report vulnerabilities to security@slatech.ai. PGP key available on request. Our service-level commitments:
- Acknowledgement within 24 hours of receipt
- Status update within 72 hours with triage assessment
- Full triage within 7 days
- Coordinated disclosure timeline default 90 days, negotiable
We do not bring legal action against good-faith security research conducted within the bounds of this policy. We will publicly credit researchers (or anonymise on request) on closed reports.
Procurement questions, answered
Where is customer data hosted?
How do you handle PHI / PII?
Are you SOC 2 compliant?
What's the disclosure policy?
Can I get a penetration test report?
Do you offer SSO?
Need a custom controls walkthrough?
Enterprise procurement teams get a 60-min security questionnaire walkthrough on request.
Buyer evaluation tools
Four self-serve tools for evaluating SLAtech (or any AI chatbot vendor) without a sales call: