Trust center

Built to the standard of the evidence it holds.

We handle sensitive forensic evidence every day. This page is how we protect it, control by control.

AES-256 at rest
dedicated auto-rotating keys
TLS 1.2+ in transit
signed URLs for evidence intake
Per-client isolation
cryptographic, case by case
MFA everywhere
no long-lived credentials
7-year audit logs
every access, every operation
SOC 2 Type 2
on our roadmap
Privileged matters
retained through your counsel
Named examiner
signs every conclusion
Mutual NDA
standard on every engagement
Controls

The platform, control by control.

Infrastructure

01

AWS-hosted on hardened, private infrastructure with WAF protection. All workloads run in sandboxed containers with no outbound network access and read-only filesystems, and container images are scanned on every build.

Data protection

02

All data is encrypted at rest with AES-256 using dedicated, auto-rotating keys, and TLS 1.2+ in transit. Evidence uploads go directly to encrypted storage via signed URLs, and per-client cryptographic isolation means you only ever see your own record.

Access and identity

03

MFA is enforced across all access, with role-based permissions and least-privilege enforcement. There are no long-lived credentials anywhere: all access is short-lived, scoped and auditable, and internal systems are restricted by IP allowlisting.

Logging and response

04

A full audit trail covers every access, operation and data event, with automated threat alerting. Logs are retained for seven years for forensic audit readiness.

Retention and continuity

05

Preserved evidence cannot be modified or deleted once stored. Automated backups run with point-in-time recovery, and chain of custody holds from intake through disposition.

AI governance

06

Your data is never used to train models. Automated examination is reviewed by human examiners before anything reaches you, with strict data boundaries between clients, cases and models.

Evidence handling

Chain of custody, end to end.

01

Intake

Evidence and events enter through read-only connectors or signed upload URLs, hashed and attributed to their source on arrival.

02

Preservation

Once stored, the record cannot be modified or deleted. Every item carries its provenance, and backups run with point-in-time recovery.

03

Examination

Access is purpose-bound and logged. Examiners see what the pipeline routes to them, inside per-client isolation.

04

Disposition

Chain of custody holds through the end of the engagement, with legal holds honored and every conclusion documented in writing.

Working with us

Confidentiality is the default.

Every engagement runs under a standard mutual NDA, and for privileged matters we accept retention through outside counsel. SOC 2 Type 2 is on our roadmap. For security documentation or to submit a questionnaire, write to security@excavate.ai.