TRUST CENTER

Security, privacy and AI governance,
documented.

How we protect your data, what our AI is permitted to do, and where your data lives — backed by evidence, not adjectives.

SOC 2 Type IIGDPRSovereign deploymentNo external LLM
ISSUED BY SIRP Labs Inc.VERSION 1.0 · 21 July 2026CONTACT [email protected]

Overview

OmniSense is an AI-native Security Operations platform for regulated, sovereign and critical-infrastructure environments. This page sets out our security, privacy and AI-governance posture in one place, so your security, procurement and data-protection teams can assess us without a questionnaire cycle. Where a capability is evidenced today, we say so; where it is in progress, we say that too.

RequirementStatusDetail
SOC 2 Type IIEvidencedSecurity, Availability and Confidentiality. Unqualified opinion, no exceptions noted. Report available under NDA.
GDPREvidencedData Processing Agreement and Standard Contractual Clauses available; data-residency and retention controls.
Sovereign / in-country deploymentEvidencedRegional deployment with in-boundary AI reasoning; air-gapped tier available.
ISO 27001In progressAligned to the standard; certification engagement to be scoped.
Independent penetration testingEvidencedPerformed quarterly by an independent third-party firm; findings remediated to defined SLA. The report itself is not released; cadence, scope and remediation practice can be discussed under NDA.
FedRAMP / IL5 / CMMCNot claimedNot claimed.
On certifications

We do not market certifications we do not hold. Where we hold an attestation, we share the report itself under NDA — including the auditor’s test results, not just a logo.

The attestation

ReportSystem and Organization Controls (SOC 2) Type II
AuditorAccorp Partners CPA LLC (License PAC-FIRM-LIC-47383)
Examination period1 March 2025 – 15 August 2025
Report issued12 October 2025
CriteriaSecurity · Availability · Confidentiality
OpinionUnqualified (clean): controls suitably designed and operating effectively throughout the period
Test results“No exception noted” across the tested controls
Examined infrastructureAmazon Web Services and Microsoft Azure, United States regions. AWS and Azure are carved-out subservice organisations.
AvailabilityFull report under NDA. A bridge letter covering the period since 16 August 2025 is available on request.
Scope, stated precisely

The attestation covers the SIRP Labs control environment and the infrastructure described above. Deployments in other regions, including EU, KSA, Pakistan and air-gapped customer environments, operate under the same organisational control programme, but were not themselves inside the examined infrastructure boundary for that period. Extending audit scope to additional regions is planned for the next examination cycle. We would rather you read the report and find it matches what we told you.

AI trust

Most trust centers answer SOC 2. Few answer the question that matters when the software makes decisions: what is your AI permitted to do without asking us?

Where the reasoning runs

Sovereign and air-gapped deployments

All AI inference executes inside your boundary, on infrastructure you control. No external or third-party public LLM service is in the production reasoning path, and no security or customer data is transmitted to any model provider.

Cloud and hybrid deployments

Inference runs within your selected region. Where a third-party model provider is used, it is named in the sub-processor list with the data categories it receives.

Tenant-scoped learning

We do not train foundation models on your data. The platform adapts to your environment using your analysts’ own decisions and outcomes, and that learning never leaves your tenant. Cross-tenant intelligence, where enabled, shares derived insights only, never raw data, under privacy-preserving controls, and is disabled entirely in air-gapped deployments.

AI governance controls

Autonomy is governed, and the limits are in code

Human oversight on consequential actions. The platform is a co-analyst, not an autopilot.

Authority is enforced in application logic, not in model prompts. The reasoning cannot exceed the authority you grant it, and cannot argue its way past a control.

Incident closure always requires a human decision. The system recommends; a person decides.

You set the line. Configurable authority levels, from mandatory approval through to higher autonomy for defined low-risk action classes, with human override at all times.

Every decision is reproducible

Evidence-grounded verdicts. Each verdict identifies the specific evidence and sources relied upon, and what was set aside, with a confidence score.

Full decision trail from alert to action, retained and reviewable for internal audit and regulatory review.

Release discipline. Changes are validated against a frozen regression set before release, so behaviour does not drift silently between versions.

Regulatory alignment

The architecture is aligned to the principles emphasised for AI used in consequential settings (human oversight, traceability, logging, technical documentation and risk management), including the EU AI Act (obligations for general-purpose AI models with systemic risk enforceable 2 August 2026), NIS2 and DORA evidentiary needs, and sovereign frameworks such as the KSA NCA and Türkiye BDDK/KVKK regimes. We can support your own assessment with system documentation and decision-trail evidence.

Data residency and deployment

You choose where your data lives and where the reasoning happens.

Deployment modelData residencyAI inferenceExternal LLM
CloudSelected sovereign regionIn-regionNamed in sub-processors if used
HybridCustomer environment + regionIn-regionNamed in sub-processors if used
Sovereign / on-premisesCustomer data centreInside customer boundaryNone
Air-gappedCustomer data centre, isolatedCustomer-hosted, isolatedNone. Nothing leaves the boundary
  • Regional deployments are available in the European Union (Microsoft Azure), Kingdom of Saudi Arabia (Oracle Cloud Infrastructure, Riyadh), United States (Amazon Web Services / Microsoft Azure / DigitalOcean) and Pakistan (Khazana). Air-gapped deployments run entirely on customer-owned infrastructure.
  • Tenant isolation is structural. It is enforced at the data-access layer rather than by application-level filtering.
  • Encryption in transit (TLS 1.2+) and at rest; credentials and secrets stored encrypted and segregated from application data.
  • Per-request compliance controls govern logging verbosity, PII redaction level and data residency.
  • Retention and deletion are configurable; data is returned or deleted on termination in accordance with the agreement.

Controls

Grouped as assessed under the Trust Services Criteria. Full control-by-control detail is available under NDA.

Infrastructure security

  • Production environment access restricted and reviewed
  • Unique authentication enforced for production databases
  • Encryption key access restricted to authorised personnel
  • Network segmentation with deny-by-default firewalls
  • Multi-factor authentication enforced for engineering access
  • Infrastructure time synchronisation (NTP)

Organisational security

  • Employee background checks performed
  • Security awareness training on hire and annually
  • Policy acknowledgement on hire and annually
  • Code of business conduct maintained and communicated
  • Asset inventory maintained
  • Documented disciplinary process for security violations

Product security

  • Role-based access control on least privilege
  • Tenant isolation enforced at the data-access layer
  • Encryption in transit and at rest
  • Secure development lifecycle with mandatory peer review
  • Branch protection on protected repositories
  • Dependency and secret scanning in the pipeline
  • Quarterly external penetration testing by an independent third party

Internal security procedures

  • Change management, authorised before production
  • Documented incident response and escalation
  • Vendor and sub-processor risk assessment
  • Annual risk assessment and management review
  • Business continuity and disaster recovery plans established
  • Scheduled, encrypted backups with integrity verification
  • Capacity and availability monitoring with alerting
  • Logging, audit trail and periodic access reviews
  • Vulnerability management with defined remediation service levels

Data and privacy

  • Data classification policy established
  • Data retention procedures established
  • Customer data returned or deleted on termination
  • Per-request PII redaction and residency controls
Policy set

A documented information-security policy set is maintained, covering information security, access control, risk management, change management, incident management, encryption, data classification, retention, backup, business continuity, disaster recovery, vendor management, physical security, media disposal, endpoint security, password, acceptable use, vulnerability management and code of business conduct — with acknowledgement on hire and annually, managed through a continuous control-monitoring platform.

Sub-processors and data handling

Infrastructure sub-processors

Sub-processorRoleRegionData
Amazon Web ServicesCloud infrastructureUnited StatesPlatform and customer security data (US deployments)
Microsoft AzureCloud infrastructureUS / EUPlatform and customer security data (US and EU deployments)
Oracle Cloud InfrastructureCloud infrastructureSaudi Arabia (Riyadh)Platform and customer security data (KSA sovereign deployments)
KhazanaCloud infrastructurePakistanPlatform and customer security data (Pakistan deployments)
DigitalOceanCloud infrastructureUnited StatesPlatform workloads (US deployments)

Corporate sub-processors

Sub-processorRoleRegionData
SprintoContinuous compliance monitoringUnited StatesEmployee and policy-acknowledgement records; control evidence
Google WorkspaceEmail and collaborationUnited StatesSIRP Labs employee data; business correspondence
GitHubSource code management and buildUnited StatesSource code and build metadata; no customer security data
AI sub-processors

For sovereign and air-gapped deployments, no third-party model provider receives customer data, and therefore none appears as a sub-processor for AI inference. Where a model provider is used in a cloud deployment, it is named explicitly with the data categories it receives.

Data we process

CategoryDetail
Customer security telemetryAlerts, logs and events from the customer environment, which may contain personal data such as usernames, IP addresses and device identifiers.
Customer account dataNames, business email addresses and role information for platform users.
Employee dataPersonal data of SIRP Labs personnel, processed for employment and access-control purposes.

Frequently asked

Disclosure and contact

Vulnerability disclosure

We welcome reports from security researchers and customers. We acknowledge reports on receipt, keep reporters updated through remediation, and do not pursue researchers acting in good faith. Vulnerabilities identified through our quarterly independent testing programme are remediated to defined service levels.

PurposeContact
Security and trust enquiries[email protected]
Vulnerability disclosure[email protected]
Data protection / privacy[email protected]
Commercial[email protected]

This page summarises SIRP Labs Inc.’s control posture at the date of issue. It is a summary and not a substitute for the SOC 2 Type II report, which is available under NDA. Posture is reviewed continuously and customers under contract are notified of material changes.

Questions we haven't answered here?

Full SOC 2 report, DPA, sub-processor detail and pen-test cadence — available under NDA.