PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

aisecurity.llc

Security Practices

This page states the security controls we use to protect aisecurity.llc workspaces, service workflows, evidence artifacts, generated packets, integrations, and professional-services delivery, and the current implementation state of each one. AI Security LLC is an early-stage vendor with capability-specific maturity; we do not claim SOC 2, ISO 27001, HIPAA, PCI, or other formal certification unless expressly stated in a signed agreement or updated Trust Center notice.

Public policy summaryNo formal certification claimed

We use layered technical and organizational controls to protect customer workspaces, packets, evidence, and service delivery paths. Public forms are for preliminary, non-sensitive information only. Sensitive targets, credentials, regulated data, and production evidence should travel only through the approved agreement path and secure channel for the engagement.

Control States

Every control below is assigned one of six explicit states instead of hedged language like "where available" or "where applicable."

Implemented

In place today as an operational or organizational control.

Partially Implemented

In place for some but not all covered systems, features, or artifact types; the note explains the gap.

Customer Configured

Available, but the customer or workspace admin enables, configures, or enforces it.

Deployment Dependent

Depends on the specific deployment, infrastructure provider, or AI Provider in use.

Planned

Not yet in place; on our roadmap.

Not Applicable

Not currently claimed or not applicable to this surface.

Scope of These Practices

These practices apply to the public website, trust center, and legal pages; the platform and customer portal web UI; Workbench Copilot and other LLM-powered chat; /scope and /start intake workflows; generated packets, reports, and evidence packs; private offers, contracts, and SOW workflows; roles, entitlements, seats, and delegated legal, finance, IT, and security contacts; LMS, Academy, and Workforce Readiness seats or modules; Stripe checkout and subscription workflows; SSO, SAML, OIDC, and SCIM enterprise onboarding; OAuth and SaaS integrations, connectors, and customer-configured linkages; the browser extension and native app, where enabled; AI Security Workbench tools; and professional-services delivery and pentest/red-team readiness workflows.

Identity

ControlStateNote
Account, organization, and workspace segmentationImplemented
Single sign-on (SAML/OIDC) for enterprise workspacesCustomer ConfiguredAvailable for enterprise workspaces; the customer's admin sets it up and enforces it for their tenant.
SCIM provisioning and deprovisioningCustomer ConfiguredEnabled and mapped by the customer's identity team where the integration is used.
Multi-factor authenticationCustomer ConfiguredAvailable for enterprise access and administration; enablement and enforcement are set by the customer admin.

Access

ControlStateNote
Role-based access control within a workspaceImplemented
Least-privilege internal access to production systemsImplemented
Delegated legal/finance/procurement vs. technical/security role separationImplemented
Access revocation on offboarding or role changeImplementedApplies to both internal access and customer-managed workspace access.
Third-party integration OAuth scope minimizationCustomer ConfiguredThe customer grants and can revoke the scopes an integration receives.

Secrets

ControlStateNote
No secrets accepted through public formsImplemented
Secrets and credentials handled via approved storage practicesImplemented
Secrets not committed to source controlImplemented
Credentials and secrets prohibited in partner and OEM representative fixturesImplementedUnless explicitly required and separately protected under the partner agreement.

Encryption

ControlStateNote
TLS for data in transitImplemented
Encryption at restDeployment DependentDepends on the infrastructure or storage provider used for the specific data store.

Logging

ControlStateNote
Authentication and security event loggingImplemented
AI-assisted workflow audit trailsPartially ImplementedIn place for the workflows where audit trails are needed for support, security, or incident response; not every AI-assisted interaction is separately audited.
Diagnostic logging in browser extension / native appCustomer ConfiguredDepends on the enabled feature and customer configuration.

Monitoring

ControlStateNote
Availability and security monitoring for platform systemsImplemented
Vulnerability disclosure channel monitored for incoming reportsImplemented
Continuous third-party security monitoring / audited SOC-style programNot ApplicableNot currently claimed; see Certification and Assurance Status.

Infrastructure

ControlStateNote
Hosting, CDN, database, and storage via reviewed providersImplemented
Access reviews and offboarding for production and support accessImplemented

Secure SDLC

ControlStateNote
Security-sensitive changes reviewed before production releaseImplemented
Vendor and subprocessor review before adoptionImplemented

Dependencies

ControlStateNote
Dependency and vulnerability management as part of the operational baselineImplemented

Evidence Protection

Security evidence is treated differently from ordinary contact data because it may describe systems, targets, vulnerabilities, prompts, logs, traces, architecture, or customer review materials.

ControlStateNote
Evidence minimized to scoped workImplemented
Approved channels used for sensitive uploads and packet exchangeImplemented
Restricted material not accepted through public formsImplemented
Packet/report access limited to legitimate needImplemented
Redaction and masking before sharing broader copiesPartially ImplementedApplied case by case before broader sharing; not a single automated redaction pipeline covering every artifact type.
Retention and deletion per applicable policy and agreementImplemented
Stricter SOW, DPA, ROE, or evidence-handling instructionsCustomer ConfiguredControls when the customer's agreement specifies stricter terms than this baseline.

Incident Response

ControlStateNote
Defined incident contact path and escalation flowImplemented
Vulnerability disclosure intake and triageImplementedSee the Vulnerability Disclosure Policy for scope and response expectations.
Data-processing incident notice and cooperationImplementedThe process exists; specific notice timelines and procedures are set in the applicable DPA or SOW.

Business Continuity

ControlStateNote
Backups and recovery per underlying infrastructure providerPartially ImplementedRelies on the backup capabilities of the infrastructure provider for each system; not a unified, independently tested plan.
Formal, independently tested business continuity / disaster recovery planNot ApplicableNot currently claimed.

Customer Responsibilities

ControlStateNote
Assign appropriate users, roles, and delegated contactsCustomer Configured
Avoid submitting secrets through public formsCustomer Configured
Identify sensitive, regulated, or third-party data before sharing itCustomer Configured
Connect only integrations the customer is authorized to use or administerCustomer Configured
Revoke access when it is no longer neededCustomer Configured
Approve testing only through the applicable SOW, ROE, or engagement pathCustomer Configured
Provide accurate scope and authorization informationCustomer Configured
Review generated packets and deliverables before external useCustomer Configured

AI Providers

ControlStateNote
Customer data not used to train public AI modelsImplemented
Vendor review before adopting an AI ProviderImplemented
Which AI Provider is used and how it processes dataDeployment DependentVaries by feature, Hosted Deployment vs. Customer-managed Deployment, and agreement.
Human review before consequential AI-assisted deliverablesImplemented

Partner Integrations

Partner deployments identify supported versions, invocation paths, authentication or entitlement controls, diagnostic access, update handling, escalation contacts, and responsibility for the product, engine, integration, and end-customer communication.

ControlStateNote
Least required access for the agreed capability and support scopeImplemented
Credentials and secrets not placed in representative fixturesImplemented
Connected and offline update pathsDeployment DependentFollows the production agreement for that OEM or partner relationship.
Support data limited to the approved diagnostic and evidence boundaryImplemented
End-customer incident communication ownershipDeployment DependentThe partner remains the end-customer communication owner unless another model is explicitly agreed.

Workbench

Controls specific to Workbench Copilot and other AI Security Workbench features.

ControlStateNote
Copilot assists within enabled features and configured permissionsImplemented
Final findings, attestations, and claim language require human reviewImplemented
Customer data not used to train public AI modelsImplemented
Restricted material requires the applicable agreement and secure processing pathImplemented

Academy

Academy and Workforce Readiness seats and modules run on the same platform and inherit the Identity, Access, Encryption, Logging, and Evidence Protection controls described above. We do not separately claim additional Academy-specific controls beyond those. Learner and candidate data handling is governed by the Privacy Policy and, where personal data is processed on a customer's behalf, the applicable DPA.

Certification and Assurance Status

AI Security LLC is an early-stage vendor. Product and deployment maturity varies by capability and is stated on the relevant product or pilot page. We do not currently claim SOC 2, ISO 27001, HIPAA, PCI, FedRAMP, or similar certification unless a signed agreement or updated Trust Center notice says otherwise.

Until formal certifications are available, customers should rely on the control states above, the signed agreement path, packet-specific controls, and direct due diligence.

Key Terms

AI Security Workbench
The hosted platform and product surface (also called the "Workbench") that provides scoping, packet generation, security analysis tools, Workbench Copilot, evidence handling, and related AI-security features to customers.
Hosted Deployment
A deployment model where aisecurity.llc operates the infrastructure, platform, and AI Provider connections used to deliver the Services.
Customer-managed Deployment
A deployment model where the customer operates some or all of the infrastructure, AI Provider connections, or execution environment, subject to the applicable agreement. Security and processing characteristics for a Customer-managed Deployment depend on that customer's own configuration and are not identical to a Hosted Deployment.
Evidence
Logs, traces, screenshots, findings, packets, reports, questionnaire materials, and other artifacts generated or collected to document a service, assessment, or governance activity.
Evidence Boundary
The agreed limit on what Evidence is collected, retained, shared, or published for a given engagement, as set by the applicable SOW, Evidence Handling Policy, Data Retention & Redaction Policy, or customer instruction.

Found a security issue?

Report vulnerabilities responsibly via our Vulnerability Disclosure Policy or email security@aisecurity.llc.

Security Practices - aisecurity.llc - Last updated June 27, 2026 · Version 2.0

<- Back to Trust Center