Trust Center

Security at the Core

DataFuse is built on a cryptographically decoupled architecture that keeps your credentials out of LLM context windows. Here you'll find everything about our security posture, compliance certifications, and privacy practices.

Compliance

Independently verified certifications and compliance standards.

SOC 2 Type II

Certified

Our systems and controls have been independently audited and certified for security, availability, and confidentiality.

ISO 27001:2022

Certified

Our Information Security Management System meets the rigorous international standard for information security.

GDPR Compliant

Compliant

Full compliance with EU data protection regulations including data subject rights and cross-border data transfers.

Security Controls

Continuously monitored and verified

Infrastructure Security

  • Encryption keys access restricted
  • Production infrastructure access restricted
  • Remote access encrypted enforced
  • Firewall rules and network segmentation enforced
  • Infrastructure monitoring and alerting enabled

Organizational Security

  • Asset disposal procedures utilized
  • MDM system enforced on company devices
  • Background checks completed for employees
  • Security awareness training conducted annually

Product Security

  • Data encryption at rest and in transit
  • Control self-assessments conducted quarterly
  • Penetration testing performed annually
  • Vulnerability scanning and remediation process
  • Secure SDLC practices enforced

Internal Security Procedures

  • Business Continuity & Disaster Recovery plans established
  • SOC 2 system description documented
  • Organization structure and access policies documented
  • Incident response plan tested and maintained
  • Change management process enforced
  • Vendor risk assessment program in place
  • Access reviews conducted quarterly

Data and Privacy

  • Customer data deleted upon account termination
  • Data classification policy enforced
  • Privacy impact assessments conducted
  • Consent management system in place

Resources

Audit reports, policies, and security documentation. Request access to locked documents.

Audit Reports

DataFuse - SOC 2 Type II Report

Our most recent SOC 2 Type II audit report

DataFuse - ISO/IEC 27001:2022 Certificate

ISMS certification documentation

Policies

Business Continuity and Disaster Recovery Plan

Procedures for maintaining operations during disruptions

Incident Response Plan

Procedures for detecting, responding to, and recovering from security incidents

Data Management Policy

How we collect, process, and protect customer data

Secure Development Policy

Security requirements across our software development lifecycle

Information Security Policy

Overarching security governance framework

Other Resources

DataFuse Web Application Penetration Test Summary

Executive summary of our latest penetration test

Engagement Letter

Third-party audit engagement details

Subprocessors

Third-party services that process data on our behalf.

Provider Purpose Region
Amazon Web Services
Hosting our infrastructureus-east-1 (N. Virginia)
Cloudflare
DNS, CDN, and edge securityGlobal (Anycast)
Vercel
Application hosting and deploymentus-east-1 (N. Virginia)
Datadog
Infrastructure monitoring and alertingUS1 (AWS us-east-1)

Frequently Asked Questions

Common questions about DataFuse's security practices.

Updates

Latest security and compliance news from DataFuse.

SecurityMay 2026

Statement of Non-Impact: Recent Cloudflare Outage

DataFuse infrastructure was not impacted by the recent Cloudflare incident. Our multi-region failover ensured continuous uptime.

ComplianceMarch 2026

Updated SOC 2 Type II report published

Our latest SOC 2 Type II audit report covering Jan 2025 — Jan 2026 is now available upon request.

GeneralJanuary 2026

DataFuse Trust Center launched

We've launched our Trust Center to provide full transparency into our security posture, compliance status, and practices.

Have a security question?

Our security team is happy to answer any questions about our practices, request additional documentation, or schedule a call.

Contact Security Team