Trust Center
PenfieldAI is designed to run in your environment. Customer data stays in your network, under your identity, network, and infrastructure controls. This Trust Center summarizes the security capabilities that matter for vendor risk and IT security reviews.
SOC 2 Type II, ISO 27001 certificates, and penetration test summaries are available to customers and prospects upon request under NDA. Contact your Penfield representative.
Deployment model
| Principle | Description |
|---|---|
| Customer-hosted | Penfield deploys into your Kubernetes or OpenShift cluster, in a dedicated namespace. |
| Data residency | Application data remains in your environment. Penfield does not require customer data to be sent to Penfield for core product operation. |
| Private access | The application is intended to be reachable over your VPN or internal network, not exposed directly to the public internet. |
| Your standards | You retain control of the cluster, network perimeter, identity provider, TLS certificates, and storage encryption. |
For deeper detail, see Architecture & network, Data & encryption, and Identity & access.
Compliance
SOC 2 Type II
SOC 2 Type II evaluates controls relevant to security, availability, processing integrity, confidentiality, and privacy. PenfieldAI maintains SOC 2 Type II compliance as part of our commitment to operational security.
ISO 27001
ISO 27001 is an internationally recognized standard for information security management systems (ISMS). PenfieldAI maintains ISO 27001 certification to govern how we protect information and manage security risk.
Controls at a glance
| Product Security | Infrastructure Security | Data Security | |||
|---|---|---|---|---|---|
| Role-Based Access Control | ✅ | Physical Security | ✅ | Encryption at-rest | ✅ |
| Single Sign-On (SSO) | ✅ | ZTNA / VPN | ✅ | Encryption in transit | ✅ |
| Audit Logging | ✅ | Load Balancers | ✅ | Password Hashed (Argon2id) | ✅ |
| Data Security | ✅ | TLS/SSL Support | ✅ | Data remains in your environment | ✅ |
| OWASP Standard | ✅ | Least Privilege Principle | ✅ | ||
| ⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤ | ⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤ | ⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤ | |||
Application Security | Privacy and Data Management | Reports | |||
| Secure SDLC | ✅ | Secure Data Storage | ✅ | Network Diagram | ✅ |
| Code Reviews | ✅ | Data Handling | ✅ | Architecture Diagrams | ✅ |
| Secret Detection | ✅ | Data Minimization | ✅ | Penfield App Architecture | ✅ |
| Code Analysis | ✅ | Data Storage | ✅ | Pentest Report | ✅ |
| Container Scanning | ✅ | Data at Termination | ✅ | ||
| Dependency Scanning | ✅ | ||||
| Security Vulnerabilities | ✅ | ||||
| ⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤ | ⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤ | ⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤ | |||
Access Control | Corporate Security | Security Grades | |||
| Data Access | ✅ | Email Protection | ✅ | Qualys SSL Labs | ✅ |
| Logging | ✅ | Employee Training | ✅ | ||
| Password Security | ✅ | Incident Response | ✅ | ||
| Monitoring and Logging | ✅ | Endpoint Security | ✅ | ||
| Identity Management | ✅ | ||||
| MFA | ✅ | ||||
| ⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤ | ⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤ | ⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤ | |||
Policies | Legal & HR | Support | |||
| Acceptable Use Policy | ✅ | Privacy Policy | ✅ | Customer Support | ✅ |
| Access Control Policy | ✅ | Background Check | ✅ | SLA | ✅ |
| Information Security Policy | ✅ |