Trust & Security

We treat your data
like it was ours.

Enterprise-grade security practices, transparent subprocessors, and a compliance roadmap you can verify. No vague assurances — specific commitments, in writing.

Security by design

Six commitments we actually enforce.

Encryption everywhere

AES-256 encryption at rest for all stored data. TLS 1.3 for data in transit. Client credentials and API keys are stored in encrypted vaults, never in source code.

No data training

Client data, conversations, and documents are never used to train AI models. Our Claude integration uses the API with zero-retention settings where available.

Background-checked team

Every consultant who may access client systems or data undergoes background verification. Access is granted on a least-privilege basis and reviewed quarterly.

NDA-first engagements

We sign mutual NDAs before any scoping call that could reveal sensitive information. Your IP stays yours — repositories, prompts, and eval suites are handed over cleanly.

Isolated environments

Client instances and data are logically separated. Development, staging, and production environments use distinct credentials and network segmentation.

Audit trail by default

Every action an agent takes is logged. Every configuration change is documented. You get full access to logs, runbooks, and change history from day one.

Compliance roadmap

Where we are, and where we are headed.

In progress

SOC 2 Type II

Target: Q1 2027

Audit scheduled with independent assessor

Planned

ISO 27001

Target: Q3 2027

Framework mapping complete; implementation underway

Active

GDPR compliance

Target: Live

Data processing agreements available on request

Active

Background checks

Target: Live

All client-facing staff verified annually

Subprocessors

Who else touches your data, and why.

We keep this list short and current. If we add a subprocessor that could access client data, we notify affected clients 30 days in advance.

VendorPurposeData involvedLocation
AnthropicClaude API — AI reasoning and agent responsesConversation transcripts, no client PII unless explicitly sharedUS (with zero-retention where available)
VercelStatic site hosting and edge functionsWebsite content, form submissions, analyticsGlobal edge
ServiceNowPlatform implementation and managed servicesPlatform configuration, workflow data, incident recordsClient instance — client-controlled
Incident response

What happens if something goes wrong.

We maintain a written incident response plan reviewed quarterly. Every consultant knows the escalation path.

Detection

Automated monitoring + client reporting channels. PagerDuty for critical alerts.

Notification

Client notified within 24 hours of confirmed incident. Initial assessment within 4 hours for P1.

Resolution & RCA

Fix deployed, then root cause analysis shared within 72 hours with preventive measures.

Security contacts
security@ifbash.com

For security questionnaires, audit requests, and incident reports.

Responsible disclosure

Found a vulnerability? Email security@ifbash.com with details. We respond within 48 hours and credit researchers who report responsibly.

Data residency

Client data stays in the region you specify where technically feasible. ServiceNow instances are region-bound by default.

FAQ

Security questions we hear a lot.

Ask our security team

For ServiceNow work, data lives in your ServiceNow instance — we do not host it. For AI agents we build, conversation data is processed via the Claude API (US-based, with zero-retention settings) and stored only where you explicitly configure retention. Web form data is stored in Vercel edge infrastructure.

Need our security questionnaire?

We share our full security pack — questionnaire, subprocessors list, incident response plan, and compliance roadmap — under NDA within one business day.