Platform · Security
Your data is safe. Your build is yours.
Data sovereignty is the first thing procurement and legal ask about, so we lead with it. Single-tenant by design, encrypted end to end, and never trained on. Your workflows and anything we build are yours to keep. Hosted on AWS, SOC 2 Type II, independently audited by Prescient Assurance.
01Data sovereignty
Your data, your workflows, your IP
It is the first question you should ask any AI vendor, so here is the plain answer. Everything you build on the platform is yours: the workflows, the integrations, and any software we build for you. The only thing that is ours is the operating model and the enforcement layer underneath. Whatever you build stays on your own farm.
01
Single-tenant, isolated.
Your operation runs in its own tenant. We never pool your data with other customers and never use it for your competition.
02
We never train on your data.
Agents are grounded in your data to do the work, not to train a model. Your data does not make anyone else’s agents smarter, and it trains nothing external.
03
You own the build.
The operating model, the workflows, and any software we build for you are yours: owned by you, portable, and covered by IP ownership of your outputs. Not broker-owned.
04
You control access.
Data residency in US, EU, or Canada. Role-based access, human-in-the-loop gates, and an immutable audit trail on every action.
05
We expand the honest way.
Some vendors get in on one use case, then use the data access to grow. Because you own everything built on your data, the only reason we grow inside your business is that the first workflow paid for itself and you asked for the next one. If we don’t earn workflow two, we don’t get it. It is in writing in the MSA.
An ungoverned agent is an unpriced liability.
Every agent acting outside a model of your business is risk you haven't booked yet. Authentica makes the risk legible: one model of how you run, one gate, one audit trail.
02Compliance and audit
Independently verified
Our security posture is validated by independent auditors and continuous third-party testing, not internal checklists.
01
SOC 2 Type II
Independently audited by Prescient Assurance across security, availability, and confidentiality, with continuous monitoring. Report available to customers under NDA.
02
Penetration testing
Regular third-party tests against the platform and infrastructure. Results available to customers under NDA.
03
Audit trails
An immutable log of every action, decision, and data change, down to each agent action. Show an auditor exactly what happened, when, and by whom.
Every one of those actions traces back to the operating model your agents run on. Read the white paper: The model is not the product.
03Infrastructure
Hosted on AWS. Protected at the edge.
The Authentica platform runs on Amazon Web Services with multiple layers of network protection between the public internet and your data.
01
Private VPC architecture
All services deployed within private subnets with no direct internet exposure. Traffic is routed through load balancers with least-privilege security groups.
02
DDoS mitigation and WAF
Web application firewall and DDoS protection at the edge filter malicious traffic before it reaches the platform. Rate limiting blocks credential stuffing and bot attacks.
03
Key management
Encryption keys managed through AWS KMS backed by hardware security modules. Keys are rotated automatically and never leave the HSM boundary.
04Data protection
Your data. Your rules.
End-to-end encryption, regional data residency, and GDPR-ready controls, so you stay compliant without slowing down.
01
Encryption everywhere
AES-256 encryption at rest and TLS 1.3 in transit. Your data is protected whether it is stored or moving between systems.
02
Data residency
Choose where your data lives: US, EU, or Canada. Meet regulatory requirements and internal governance policies with region-specific deployment.
03
GDPR ready
Data processing agreements, right-to-erasure workflows, and consent management built into the platform. Ready for your DPA review on day one.
Security you can trust
Have questions about our security posture? We are happy to walk through our compliance documentation, SOC 2 report, and architecture with your team.