Trust & security

Designed for the auditor in the room.

Closora is built for the controller, the CISO, and the auditor in the same meeting. Every consequential action is logged, reversible, and bounded by policy.

Certifications

SOC 2 Type II

Annual audit. Report available under NDA from your sales contact.

Certifications

ISO/IEC 42001

First AI management certification in our category.

Certifications

ISO 27001 · 27701

Information security and privacy management.

Regulations

EU AI Act

High-risk system conformance with documented model cards.

Regulations

GDPR · CCPA

DPA, SCCs, and right-to-erasure workflows.

Regulations

HIPAA · FedRAMP

Available on Enterprise tier with VPC deployment.

Architecture

Defense in depth.

Tenant isolation at compute, data, and model layer. Prompt-injection defenses. Output validation. Per-tenant KMS keys with BYOK on Enterprise.

  1. Identity

    SSO via SAML/OIDC. SCIM provisioning. Per-action RBAC. JIT access for high-risk operations.

  2. Data

    AES-256 at rest. TLS 1.3 in transit. Per-tenant KMS keys; BYOK on Enterprise tier. PII redaction at ingress.

  3. Network

    VPC peering and PrivateLink. Egress allowlisting. Cloudflare DDoS & WAF.

  4. Agent safety

    Tool allowlists per agent. Prompt-injection input filtering. Output validators on every tool call.

  5. Audit

    Append-only log of every agent step. Exportable to your SIEM. 7-year retention available.

  6. Resilience

    Multi-region. 99.95% uptime SLA on Enterprise. Quarterly DR exercises.

Trust center

Request our compliance pack.