aisecurity.llc
Security Practices
This page states the security controls we use to protect aisecurity.llc workspaces, service workflows, evidence artifacts, generated packets, integrations, and professional-services delivery, and the current implementation state of each one. AI Security LLC is an early-stage vendor with capability-specific maturity; we do not claim SOC 2, ISO 27001, HIPAA, PCI, or other formal certification unless expressly stated in a signed agreement or updated Trust Center notice.
We use layered technical and organizational controls to protect customer workspaces, packets, evidence, and service delivery paths. Public forms are for preliminary, non-sensitive information only. Sensitive targets, credentials, regulated data, and production evidence should travel only through the approved agreement path and secure channel for the engagement.
Control States
Every control below is assigned one of six explicit states instead of hedged language like "where available" or "where applicable."
In place today as an operational or organizational control.
In place for some but not all covered systems, features, or artifact types; the note explains the gap.
Available, but the customer or workspace admin enables, configures, or enforces it.
Depends on the specific deployment, infrastructure provider, or AI Provider in use.
Not yet in place; on our roadmap.
Not currently claimed or not applicable to this surface.
Scope of These Practices
These practices apply to the public website, trust center, and legal pages; the platform and customer portal web UI; Workbench Copilot and other LLM-powered chat; /scope and /start intake workflows; generated packets, reports, and evidence packs; private offers, contracts, and SOW workflows; roles, entitlements, seats, and delegated legal, finance, IT, and security contacts; LMS, Academy, and Workforce Readiness seats or modules; Stripe checkout and subscription workflows; SSO, SAML, OIDC, and SCIM enterprise onboarding; OAuth and SaaS integrations, connectors, and customer-configured linkages; the browser extension and native app, where enabled; AI Security Workbench tools; and professional-services delivery and pentest/red-team readiness workflows.
Identity
| Control | State | Note |
|---|---|---|
| Account, organization, and workspace segmentation | Implemented | — |
| Single sign-on (SAML/OIDC) for enterprise workspaces | Customer Configured | Available for enterprise workspaces; the customer's admin sets it up and enforces it for their tenant. |
| SCIM provisioning and deprovisioning | Customer Configured | Enabled and mapped by the customer's identity team where the integration is used. |
| Multi-factor authentication | Customer Configured | Available for enterprise access and administration; enablement and enforcement are set by the customer admin. |
Access
| Control | State | Note |
|---|---|---|
| Role-based access control within a workspace | Implemented | — |
| Least-privilege internal access to production systems | Implemented | — |
| Delegated legal/finance/procurement vs. technical/security role separation | Implemented | — |
| Access revocation on offboarding or role change | Implemented | Applies to both internal access and customer-managed workspace access. |
| Third-party integration OAuth scope minimization | Customer Configured | The customer grants and can revoke the scopes an integration receives. |
Secrets
| Control | State | Note |
|---|---|---|
| No secrets accepted through public forms | Implemented | — |
| Secrets and credentials handled via approved storage practices | Implemented | — |
| Secrets not committed to source control | Implemented | — |
| Credentials and secrets prohibited in partner and OEM representative fixtures | Implemented | Unless explicitly required and separately protected under the partner agreement. |
Encryption
| Control | State | Note |
|---|---|---|
| TLS for data in transit | Implemented | — |
| Encryption at rest | Deployment Dependent | Depends on the infrastructure or storage provider used for the specific data store. |
Logging
| Control | State | Note |
|---|---|---|
| Authentication and security event logging | Implemented | — |
| AI-assisted workflow audit trails | Partially Implemented | In place for the workflows where audit trails are needed for support, security, or incident response; not every AI-assisted interaction is separately audited. |
| Diagnostic logging in browser extension / native app | Customer Configured | Depends on the enabled feature and customer configuration. |
Monitoring
| Control | State | Note |
|---|---|---|
| Availability and security monitoring for platform systems | Implemented | — |
| Vulnerability disclosure channel monitored for incoming reports | Implemented | — |
| Continuous third-party security monitoring / audited SOC-style program | Not Applicable | Not currently claimed; see Certification and Assurance Status. |
Infrastructure
| Control | State | Note |
|---|---|---|
| Hosting, CDN, database, and storage via reviewed providers | Implemented | — |
| Access reviews and offboarding for production and support access | Implemented | — |
Secure SDLC
| Control | State | Note |
|---|---|---|
| Security-sensitive changes reviewed before production release | Implemented | — |
| Vendor and subprocessor review before adoption | Implemented | — |
Dependencies
| Control | State | Note |
|---|---|---|
| Dependency and vulnerability management as part of the operational baseline | Implemented | — |
Evidence Protection
Security evidence is treated differently from ordinary contact data because it may describe systems, targets, vulnerabilities, prompts, logs, traces, architecture, or customer review materials.
| Control | State | Note |
|---|---|---|
| Evidence minimized to scoped work | Implemented | — |
| Approved channels used for sensitive uploads and packet exchange | Implemented | — |
| Restricted material not accepted through public forms | Implemented | — |
| Packet/report access limited to legitimate need | Implemented | — |
| Redaction and masking before sharing broader copies | Partially Implemented | Applied case by case before broader sharing; not a single automated redaction pipeline covering every artifact type. |
| Retention and deletion per applicable policy and agreement | Implemented | — |
| Stricter SOW, DPA, ROE, or evidence-handling instructions | Customer Configured | Controls when the customer's agreement specifies stricter terms than this baseline. |
Incident Response
| Control | State | Note |
|---|---|---|
| Defined incident contact path and escalation flow | Implemented | — |
| Vulnerability disclosure intake and triage | Implemented | See the Vulnerability Disclosure Policy for scope and response expectations. |
| Data-processing incident notice and cooperation | Implemented | The process exists; specific notice timelines and procedures are set in the applicable DPA or SOW. |
Business Continuity
| Control | State | Note |
|---|---|---|
| Backups and recovery per underlying infrastructure provider | Partially Implemented | Relies on the backup capabilities of the infrastructure provider for each system; not a unified, independently tested plan. |
| Formal, independently tested business continuity / disaster recovery plan | Not Applicable | Not currently claimed. |
Customer Responsibilities
| Control | State | Note |
|---|---|---|
| Assign appropriate users, roles, and delegated contacts | Customer Configured | — |
| Avoid submitting secrets through public forms | Customer Configured | — |
| Identify sensitive, regulated, or third-party data before sharing it | Customer Configured | — |
| Connect only integrations the customer is authorized to use or administer | Customer Configured | — |
| Revoke access when it is no longer needed | Customer Configured | — |
| Approve testing only through the applicable SOW, ROE, or engagement path | Customer Configured | — |
| Provide accurate scope and authorization information | Customer Configured | — |
| Review generated packets and deliverables before external use | Customer Configured | — |
AI Providers
| Control | State | Note |
|---|---|---|
| Customer data not used to train public AI models | Implemented | — |
| Vendor review before adopting an AI Provider | Implemented | — |
| Which AI Provider is used and how it processes data | Deployment Dependent | Varies by feature, Hosted Deployment vs. Customer-managed Deployment, and agreement. |
| Human review before consequential AI-assisted deliverables | Implemented | — |
Partner Integrations
Partner deployments identify supported versions, invocation paths, authentication or entitlement controls, diagnostic access, update handling, escalation contacts, and responsibility for the product, engine, integration, and end-customer communication.
| Control | State | Note |
|---|---|---|
| Least required access for the agreed capability and support scope | Implemented | — |
| Credentials and secrets not placed in representative fixtures | Implemented | — |
| Connected and offline update paths | Deployment Dependent | Follows the production agreement for that OEM or partner relationship. |
| Support data limited to the approved diagnostic and evidence boundary | Implemented | — |
| End-customer incident communication ownership | Deployment Dependent | The partner remains the end-customer communication owner unless another model is explicitly agreed. |
Workbench
Controls specific to Workbench Copilot and other AI Security Workbench features.
| Control | State | Note |
|---|---|---|
| Copilot assists within enabled features and configured permissions | Implemented | — |
| Final findings, attestations, and claim language require human review | Implemented | — |
| Customer data not used to train public AI models | Implemented | — |
| Restricted material requires the applicable agreement and secure processing path | Implemented | — |
Academy
Academy and Workforce Readiness seats and modules run on the same platform and inherit the Identity, Access, Encryption, Logging, and Evidence Protection controls described above. We do not separately claim additional Academy-specific controls beyond those. Learner and candidate data handling is governed by the Privacy Policy and, where personal data is processed on a customer's behalf, the applicable DPA.
Certification and Assurance Status
AI Security LLC is an early-stage vendor. Product and deployment maturity varies by capability and is stated on the relevant product or pilot page. We do not currently claim SOC 2, ISO 27001, HIPAA, PCI, FedRAMP, or similar certification unless a signed agreement or updated Trust Center notice says otherwise.
Until formal certifications are available, customers should rely on the control states above, the signed agreement path, packet-specific controls, and direct due diligence.
Key Terms
- AI Security Workbench
- The hosted platform and product surface (also called the "Workbench") that provides scoping, packet generation, security analysis tools, Workbench Copilot, evidence handling, and related AI-security features to customers.
- Hosted Deployment
- A deployment model where aisecurity.llc operates the infrastructure, platform, and AI Provider connections used to deliver the Services.
- Customer-managed Deployment
- A deployment model where the customer operates some or all of the infrastructure, AI Provider connections, or execution environment, subject to the applicable agreement. Security and processing characteristics for a Customer-managed Deployment depend on that customer's own configuration and are not identical to a Hosted Deployment.
- Evidence
- Logs, traces, screenshots, findings, packets, reports, questionnaire materials, and other artifacts generated or collected to document a service, assessment, or governance activity.
- Evidence Boundary
- The agreed limit on what Evidence is collected, retained, shared, or published for a given engagement, as set by the applicable SOW, Evidence Handling Policy, Data Retention & Redaction Policy, or customer instruction.
Found a security issue?
Report vulnerabilities responsibly via our Vulnerability Disclosure Policy or email security@aisecurity.llc.
Security Practices - aisecurity.llc - Last updated June 27, 2026 · Version 2.0