Built to the standard of the evidence it holds.
We handle sensitive forensic evidence every day. This page is how we protect it, control by control.
The platform, control by control.
Infrastructure
01AWS-hosted on hardened, private infrastructure with WAF protection. All workloads run in sandboxed containers with no outbound network access and read-only filesystems, and container images are scanned on every build.
Data protection
02All data is encrypted at rest with AES-256 using dedicated, auto-rotating keys, and TLS 1.2+ in transit. Evidence uploads go directly to encrypted storage via signed URLs, and per-client cryptographic isolation means you only ever see your own record.
Access and identity
03MFA is enforced across all access, with role-based permissions and least-privilege enforcement. There are no long-lived credentials anywhere: all access is short-lived, scoped and auditable, and internal systems are restricted by IP allowlisting.
Logging and response
04A full audit trail covers every access, operation and data event, with automated threat alerting. Logs are retained for seven years for forensic audit readiness.
Retention and continuity
05Preserved evidence cannot be modified or deleted once stored. Automated backups run with point-in-time recovery, and chain of custody holds from intake through disposition.
AI governance
06Your data is never used to train models. Automated examination is reviewed by human examiners before anything reaches you, with strict data boundaries between clients, cases and models.
Chain of custody, end to end.
Intake
Evidence and events enter through read-only connectors or signed upload URLs, hashed and attributed to their source on arrival.
Preservation
Once stored, the record cannot be modified or deleted. Every item carries its provenance, and backups run with point-in-time recovery.
Examination
Access is purpose-bound and logged. Examiners see what the pipeline routes to them, inside per-client isolation.
Disposition
Chain of custody holds through the end of the engagement, with legal holds honored and every conclusion documented in writing.
Confidentiality is the default.
Every engagement runs under a standard mutual NDA, and for privileged matters we accept retention through outside counsel. SOC 2 Type 2 is on our roadmap. For security documentation or to submit a questionnaire, write to security@excavate.ai.