Skip to main content

Trust Center

PenfieldAI is designed to run in your environment. Customer data stays in your network, under your identity, network, and infrastructure controls. This Trust Center summarizes the security capabilities that matter for vendor risk and IT security reviews.

Looking for assurance reports?

SOC 2 Type II, ISO 27001 certificates, and penetration test summaries are available to customers and prospects upon request under NDA. Contact your Penfield representative.

Deployment model

PrincipleDescription
Customer-hostedPenfield deploys into your Kubernetes or OpenShift cluster, in a dedicated namespace.
Data residencyApplication data remains in your environment. Penfield does not require customer data to be sent to Penfield for core product operation.
Private accessThe application is intended to be reachable over your VPN or internal network, not exposed directly to the public internet.
Your standardsYou retain control of the cluster, network perimeter, identity provider, TLS certificates, and storage encryption.

For deeper detail, see Architecture & network, Data & encryption, and Identity & access.

Compliance

SOC 2 Type II

SOC 2 Type II evaluates controls relevant to security, availability, processing integrity, confidentiality, and privacy. PenfieldAI maintains SOC 2 Type II compliance as part of our commitment to operational security.

ISO 27001

ISO 27001 is an internationally recognized standard for information security management systems (ISMS). PenfieldAI maintains ISO 27001 certification to govern how we protect information and manage security risk.

Controls at a glance

Product SecurityInfrastructure SecurityData Security
Role-Based Access ControlPhysical SecurityEncryption at-rest
Single Sign-On (SSO)ZTNA / VPNEncryption in transit
Audit LoggingLoad BalancersPassword Hashed (Argon2id)
Data SecurityTLS/SSL SupportData remains in your environment
OWASP StandardLeast Privilege Principle
⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤
Application Security
Privacy and Data Management
Reports
Secure SDLCSecure Data StorageNetwork Diagram
Code ReviewsData HandlingArchitecture Diagrams
Secret DetectionData MinimizationPenfield App Architecture
Code AnalysisData StoragePentest Report
Container ScanningData at Termination
Dependency Scanning
Security Vulnerabilities
⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤
Access Control
Corporate Security
Security Grades
Data AccessEmail ProtectionQualys SSL Labs
LoggingEmployee Training
Password SecurityIncident Response
Monitoring and LoggingEndpoint Security
Identity Management
MFA
⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤⏤
Policies
Legal & HR
Support
Acceptable Use PolicyPrivacy PolicyCustomer Support
Access Control PolicyBackground CheckSLA
Information Security Policy