We take security seriously because that’s the product.
A platform that watches over your organization has to hold itself to the same standard. Here is how we approach it, conceptually — details are refined as our infrastructure matures.
Encryption
Data is encrypted in transit and at rest using industry-standard protocols.
Authentication
Strong authentication is required for access to administrative and organizational data.
Access control
Access to customer data is governed by role-based permissions tied to job function.
Least-privilege principles
Systems and personnel are granted only the access required to perform their function.
Data isolation
Each organization's data is logically separated from every other organization's data.
Auditability
Security-relevant actions are logged, so activity can be reviewed and investigated.
Secure integrations
Connections to third-party systems are scoped to the minimum access required.
Data retention
Data is retained only as long as necessary to provide the service, and is configurable per organization.
AI data boundaries
AI processing is scoped to security-relevant data and is not used to train models across customers.
Administrative controls
Organizations retain control over what Centrasprit can observe and what it is authorized to act on.
Centrasprit does not currently hold SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, or other third-party security certifications. We will update this page if and when any such certification is formally verified.