Security
NeoSigma AI is built to run in security-conscious environments. Your code and data stay private, isolated, and encrypted end to end.
Last updated: July 3, 2026
GDPR
SOC 2 audit in progress
Customer data is not stored or persisted beyond what is needed for task execution.
Every organization's data is isolated at the query layer - cross-customer access is prevented by design.
Your data is not used to train models for other customers.
Data encrypted at rest with AES-256 and in transit with TLS 1.2+.
Hosted on Google Cloud Platform (GCP) in the us-central1 region.
Application workloads run on Cloud Run - fully managed, auto-scaling, no persistent server access.
Secrets and credentials stored in GCP Secret Manager, never in source code.
Production database on Cloud SQL (PostgreSQL) with automated daily backups and point-in-time recovery.
Authentication via Google OAuth - no passwords stored by NeoSigma AI.
Role-based access control (RBAC): Admin and Member roles per organization.
Least-privilege service accounts with custom IAM roles scoped to minimum required permissions.
Production GCP access is restricted to named engineering personnel and reviewed at least quarterly.
Employee access is revoked as part of the offboarding process, targeting within 24 hours.
All code changes require peer review before merging to production.
Automated CI pipeline runs dependency audits and security checks on every pull request.
API tokens are SHA-256 hashed at rest - plaintext shown once at creation, never persisted.
Webhook signatures verified with HMAC-SHA256 and timing-safe comparison.
SOC 2 Type II audit in progress, managed through Vanta.
GDPR compliant - customer data is processed and stored in accordance with applicable data protection regulations.
Automated daily database backups with 7-day retention and point-in-time recovery.
Audit logs maintained for all security-relevant actions: logins, access changes, API key lifecycle.
Annual security policy review and incident response tabletop exercise.
We welcome reports from security researchers. Found a vulnerability? Email us at founders@neosigma.ai. We acknowledge all reports within 2 business days. We will not pursue legal action against researchers who act in good faith, stay within the stated scope, and comply with applicable law.
In-scope systems
neosigma.ai and all subdomains
NeoSigma platform application and API
NeoSigma agent runner infrastructure
Security questions? founders@neosigma.ai