Trust & Security
We treat your data
like it was ours.
Enterprise-grade security practices, transparent subprocessors, and a compliance roadmap you can verify. No vague assurances — specific commitments, in writing.
Six commitments we actually enforce.
Encryption everywhere
AES-256 encryption at rest for all stored data. TLS 1.3 for data in transit. Client credentials and API keys are stored in encrypted vaults, never in source code.
No data training
Client data, conversations, and documents are never used to train AI models. Our Claude integration uses the API with zero-retention settings where available.
Background-checked team
Every consultant who may access client systems or data undergoes background verification. Access is granted on a least-privilege basis and reviewed quarterly.
NDA-first engagements
We sign mutual NDAs before any scoping call that could reveal sensitive information. Your IP stays yours — repositories, prompts, and eval suites are handed over cleanly.
Isolated environments
Client instances and data are logically separated. Development, staging, and production environments use distinct credentials and network segmentation.
Audit trail by default
Every action an agent takes is logged. Every configuration change is documented. You get full access to logs, runbooks, and change history from day one.
Where we are, and where we are headed.
SOC 2 Type II
Target: Q1 2027
Audit scheduled with independent assessor
ISO 27001
Target: Q3 2027
Framework mapping complete; implementation underway
GDPR compliance
Target: Live
Data processing agreements available on request
Background checks
Target: Live
All client-facing staff verified annually
Who else touches your data, and why.
We keep this list short and current. If we add a subprocessor that could access client data, we notify affected clients 30 days in advance.
| Vendor | Purpose | Data involved | Location |
|---|---|---|---|
| Anthropic | Claude API — AI reasoning and agent responses | Conversation transcripts, no client PII unless explicitly shared | US (with zero-retention where available) |
| Vercel | Static site hosting and edge functions | Website content, form submissions, analytics | Global edge |
| ServiceNow | Platform implementation and managed services | Platform configuration, workflow data, incident records | Client instance — client-controlled |
What happens if something goes wrong.
We maintain a written incident response plan reviewed quarterly. Every consultant knows the escalation path.
Automated monitoring + client reporting channels. PagerDuty for critical alerts.
Client notified within 24 hours of confirmed incident. Initial assessment within 4 hours for P1.
Fix deployed, then root cause analysis shared within 72 hours with preventive measures.
For security questionnaires, audit requests, and incident reports.
Found a vulnerability? Email security@ifbash.com with details. We respond within 48 hours and credit researchers who report responsibly.
Client data stays in the region you specify where technically feasible. ServiceNow instances are region-bound by default.
For ServiceNow work, data lives in your ServiceNow instance — we do not host it. For AI agents we build, conversation data is processed via the Claude API (US-based, with zero-retention settings) and stored only where you explicitly configure retention. Web form data is stored in Vercel edge infrastructure.
Need our security questionnaire?
We share our full security pack — questionnaire, subprocessors list, incident response plan, and compliance roadmap — under NDA within one business day.