Security posture

30 controls, by domain

Single-source-of-truth for procurement, legal, and infosec stakeholders evaluating SLAtech. Each control is marked Implemented (live now), Enterprise tier (live for the Enterprise contract shape), or Target quarter (scheduled, transparent date). Report vulnerabilities to security@slatech.ai.

Compliance

5 controls

Control Status
GDPR — DSR portal, DPA on request, SCC 2021/914 for sub-processor transfers Implemented
HIPAA — BAA-eligible single-tenant deployment Enterprise tier
SOC 2 Type I report Q3 2026 target
SOC 2 Type II report Q2 2027 target
ISO 27001 certification Q4 2026 target
Data protection

5 controls

Control Status
AES-256-GCM at rest, TLS 1.2+ in transit Implemented
Multi-tenant logical isolation across all stores (SQL + vector search + blob) Implemented
PII tokenisation / redaction before AI sub-processors (opt-in uploads + visitor messages) Implemented
Hosting in your own jurisdiction available on request (Enterprise deployments) Implemented
Customer data excluded from model training pipeline (contractual + technical) Implemented
Identity

4 controls

Control Status
Argon2id password hashing, configurable per-tenant password policy Implemented
SAML SSO integration Enterprise tier
Role-based access control (RBAC) with per-tenant roles Implemented
Audit log of admin actions (login, role change, data export) Implemented
Network

4 controls

Control Status
TLS 1.2+ enforced on every endpoint; HSTS preload Implemented
Cloudflare WAF in front of every host Implemented
Per-tenant API rate limiting (60-6000 RPM by tier) Implemented
DDoS mitigation via Cloudflare upstream Implemented
Observability

4 controls

Control Status
Sentry — every backend service emits structured errors with PII scrubbing Implemented
Per-tenant audit log export Enterprise tier
Real-time uptime dashboard (status.slatech.ai) Implemented
Synthetic transaction monitoring (5-minute cadence) Implemented
Operations

4 controls

Control Status
GitOps deploy pipeline (audited via GitHub Actions) Implemented
Pre-deploy smoke tests + post-deploy QA harness Implemented
Database backups (daily, 35-day retention) Implemented
Point-in-time recovery (last 24 hours) Implemented
Vulnerability mgmt

4 controls

Control Status
Dependabot — automated dependency updates on production branch Implemented
GitHub CodeQL static analysis on every PR Implemented
External penetration test (annual) Q4 2026 target
Coordinated vulnerability disclosure policy Published below
Disclosure policy

Coordinated vulnerability disclosure

Report vulnerabilities to security@slatech.ai. PGP key available on request. Our service-level commitments:

  • Acknowledgement within 24 hours of receipt
  • Status update within 72 hours with triage assessment
  • Full triage within 7 days
  • Coordinated disclosure timeline default 90 days, negotiable

We do not bring legal action against good-faith security research conducted within the bounds of this policy. We will publicly credit researchers (or anonymise on request) on closed reports.

FAQ

Procurement questions, answered

Where is customer data hosted?
Hosting in your own jurisdiction is available on request (Enterprise deployments). The Enterprise tier offers single-tenant deployment for buyers requiring strict data isolation.
How do you handle PHI / PII?
Detected structured identifiers (email, phone, payment card, Israeli national-ID, medical-record number) are replaced with tokens before any data leaves our servers to AI sub-processors; the originals stay encrypted at rest in our own vault and are never sent to those providers. This applies to opt-in document uploads and to visitor chat messages, across all verticals. Free-text names are not auto-detected, and public website content is left as-is. Sub-processor transfers are all governed by SCC 2021/914.
Are you SOC 2 compliant?
Type I report targeted for Q3 2026; Type II the following quarter (Q2 2027). Until then, the operational controls listed on this page are independently auditable on request. ISO 27001 certification targeted for Q4 2026.
What's the disclosure policy?
Report vulnerabilities to security@slatech.ai (PGP key available on request). We acknowledge within 24 hours, provide a status update within 72 hours, and aim for full triage within 7 days. Coordinated disclosure timeline is 90 days unless mutually agreed otherwise.
Can I get a penetration test report?
An external pen-test report runs annually (next: Q4 2026). The executive summary ships to Enterprise customers under NDA. Detailed findings are available to buyers procuring above $50k ACV after NDA execution.
Do you offer SSO?
Yes — SAML SSO ships in the Enterprise tier with support for Okta, OneLogin, Azure AD, Google Workspace. SCIM provisioning is on the roadmap for Q1 2027.

Need a custom controls walkthrough?

Enterprise procurement teams get a 60-min security questionnaire walkthrough on request.

Buyer evaluation tools

Four self-serve tools for evaluating SLAtech (or any AI chatbot vendor) without a sales call:

Eval scoreboard 200-question per-vertical methodology TCO calculator Annual savings + payback period Vendor compare-tool Filter 16 vendors by 6 criteria Vendor checklist 30 procurement due-diligence questions