Security and compliance

How we protect our clients' data.

This page summarizes where each product runs, what data it holds, and which controls protect it. The full policies, product sheets, and questionnaire answers are shared on request.

Last reviewed 2026-09-26

Infrastructure
Cloudflare and Amazon Web Services, in the United States
Isolation
Per organization, enforced in the database
Encryption
TLS in transit, AES-256 at rest
Frameworks
Controls mapped to SOC 2 and ISO/IEC 27001, not externally audited
Principles

Six rules that apply to every product.

Each organization sees only its own data

In AI Compass, AI Agent Factory, and AI Academy, row-level security policies in the database separate each organization, and every server function validates the session and membership before doing any work. ARIA Graph is installed per client.

Encryption across the data lifecycle

All traffic travels over HTTPS. Databases and storage are encrypted at rest with AES-256. The API keys and credentials that clients connect are additionally encrypted with AES-256-GCM before they are stored.

Least privilege, named access

Only designated Criterium AI staff administer the infrastructure, with personal, named accounts. Each client's users work with per-organization roles, and administrative functions are verified on the server.

AI proposes, a person decides

Agent tools declare permissions and can require human approval before writing to a system. ARIA Graph findings require a person to accept them.

Your data does not train models

Criterium AI does not use client data to train models. We use AI providers through their commercial APIs, and in AI Compass and ARIA Graph the client can connect their own accounts.

Everything leaves a trail

Sensitive actions are written to audit logs, AI usage and cost are recorded per organization, and in ARIA Graph the audit log is hash-chained so tampering can be detected.

By product

Where each product runs and what it holds.

AI Compass

Where it runs
Web app on Cloudflare. Database, authentication, files, and functions on Supabase over AWS, in Oregon, United States. Multi-organization service operated by Criterium AI.
What it holds
The organization's AI governance records: use cases, portfolio, policies, risks, roadmaps, maturity assessments, uploaded documents, and the audit log.
Access
Email and password, with optional two-factor authentication through an authenticator app. Per-organization roles verified in the database and in every server function.
AI
Anthropic's Claude by default, or the client's own AI accounts, with encrypted keys. Usage and cost recorded per organization.

AI Agent Factory

Where it runs
Its own product, running on the AI Compass platform: same infrastructure, same region, and the same per-organization isolation.
What it holds
Each agent's definition (tools, guardrails, evaluation data, and oversight threshold), runs, costs, and encrypted credentials for connected systems.
Access
The same accounts and roles as AI Compass, with the same optional two-factor authentication. Each tool declares permissions and can require human approval.
AI
The same gateway as AI Compass. Agents are evaluated against a test set before they are promoted.

AI Academy

Where it runs
App on Cloudflare, with video on Cloudflare Stream and files on Cloudflare R2. Database and authentication on Supabase over AWS, in Virginia, United States.
What it holds
Learner profile, enrollments, progress, checkpoint answers, tutor conversations (deleted after 12 months), discussions, and certificates.
Access
Email and password, or a Google account. Each person can export their data and delete their account from their profile.
AI
Anthropic's Claude for the tutor, grading, and moderation. Payments are processed by Stripe; cards never pass through our systems.

ARIA MCP

Where it runs
Functions and database on Supabase over AWS, in Virginia, United States, operated by Criterium AI. Each client application is separated by its identifier.
What it holds
Conversations, per-person memory (which operators cannot read), usage and cost records, pending approvals, and the audit log.
Access
Applications authenticate with signed tokens. Operators join by invitation, with four roles.
AI
Anthropic's Claude. Tools classified by sensitivity, human confirmation on the ones flagged, and a daily spending cap.

ARIA Graph

Where it runs
Dedicated install per client. The reference install is a virtual machine on Google Cloud with TLS and administrative access only through Identity-Aware Proxy; it can also be installed in the client's own cloud.
What it holds
The client's operating knowledge: git-versioned pages, the graph, findings, identity records, and a hash-chained audit log.
Access
Passwords hashed with Argon2id and a 12-character minimum, or single sign-on through OIDC. Roles per workspace and per knowledge pack.
AI
The client's own AI accounts, with keys sealed with AES-256-GCM and cost caps per run and per month.
Certifications

Where we stand, stated precisely.

Criterium AI does not yet hold a SOC 2 report or ISO/IEC 27001 certification, and has not yet commissioned an external penetration test. Our controls are aligned with the SOC 2 Trust Services Criteria and with ISO/IEC 27001:2022 Annex A. The mapping of each control to the products is part of the documentation available on request.

SOC 2
Controls aligned, no audit report
ISO/IEC 27001
Controls aligned, not certified
Data protection
LFPDPPP, and GDPR where applicable
Sub-processors

The providers that process data on our behalf.

ProviderServiceLocationProducts
Cloudflare, Inc.Hosting, CDN, DNS, and network security; AI Academy video and filesGlobal networkAll
Supabase, Inc. (Amazon Web Services)Database, authentication, files, and server functionsUS: Oregon (AI Compass, AI Agent Factory) and Virginia (AI Academy, ARIA MCP)AI Compass, AI Agent Factory, AI Academy, ARIA MCP
Anthropic, PBCAI models (Claude) through the commercial APIUnited StatesAI Compass, AI Agent Factory, AI Academy, ARIA MCP
Resend, Inc.Transactional emailUnited StatesAI Compass, AI Agent Factory, AI Academy
Stripe, Inc.PaymentsUnited StatesAI Academy
Voyage AIText embeddings for tutor searchUnited StatesAI Academy
Functional Software, Inc. (Sentry)Error monitoringUnited StatesAI Academy
Twilio Inc.WhatsApp notifications, if the learner turns them onUnited StatesAI Academy
Upstash, Inc.Rate-limiting countersUnited StatesAI Academy
Google CloudHosting of dedicated installs that Criterium AI operatesRegion agreed with the client (United States by default)ARIA Graph

When a client connects their own AI accounts (OpenAI, Google, Microsoft Azure, or Anthropic) in AI Compass or ARIA Graph, that provider processes data under the client's contract and is not a Criterium AI sub-processor. We notify clients under contract before adding a new sub-processor.

Documentation

Policies, sheets, and questionnaires, on request.

The full documentation is shared with clients and with companies evaluating Criterium AI as a provider. Each document states which products it covers, its version, and its review date.

Policies

  • Information security policy

    The overall framework: owners, risk management, personnel, assets, policy review, and exceptions.

    All products · Version 1.0
  • Access control and identity

    How access is granted, reviewed, and removed for staff and for each product's users.

    All products · Version 1.0
  • Encryption and key management

    Encryption in transit and at rest, encryption of client credentials, and rotation of keys and secrets.

    All products · Version 1.0
  • Data classification, retention, and deletion

    Classification levels, retention periods by product, and how deletion and data-subject requests are handled.

    All products · Version 1.0
  • Backup, continuity, and recovery

    Backups by product, the restore procedure, critical dependencies, and how operations continue if a provider fails.

    All products · Version 1.0
  • Incident response

    Severities, roles, containment and recovery steps, and notification timelines for clients and data subjects.

    All products · Version 1.0
  • Secure development, change, and vulnerability management

    How each change is designed, reviewed, tested, and deployed, and how dependencies and vulnerabilities are handled.

    All products · Version 1.0
  • Vendor and sub-processor management

    How providers that process client data are assessed, contracted, reviewed, and offboarded.

    All products · Version 1.0
  • AI model governance and human oversight

    Model selection, data use, evaluation, human oversight, cost control, and transparency across the products.

    All products · Version 1.0

Security sheets by product

  • Security sheet: AI Compass

    AI Compass architecture, data flow, per-organization isolation, authentication, AI, and logging.

    AI Compass · Version 1.0
  • Security sheet: AI Agent Factory

    Tool permissions, human approval, evaluation before promotion, execution, and credentials for agents.

    AI Agent Factory · Version 1.0
  • Security sheet: AI Academy

    Architecture, learner data, payments, video, tutor AI, retention, and user rights.

    AI Academy · Version 1.0
  • Security sheet: ARIA MCP

    Application authentication, per-person memory, tool control, auditing, and spending limits.

    ARIA MCP · Version 1.0
  • Security sheet: ARIA Graph

    Dedicated install, single sign-on, per-pack permissions, hash-chained log, outbound protection, and erasure.

    ARIA Graph · Version 1.0

Contracts and questionnaires

  • Data processing agreement (template)

    The processing agreement template we sign with clients, with annexes for technical measures and sub-processors.

    All products · Version 1.0
  • SOC 2 and ISO/IEC 27001 control mapping

    Each relevant SOC 2 criterion and Annex A control, with the Criterium AI control that addresses it and its status by product.

    All products · Version 1.0
  • Standard security questionnaire answers

    Answers to the most common vendor assessment questions, ready to copy into your format.

    All products · Version 1.0

Request access

We review every request and reply within two business days. If it is approved, you receive a personal link valid for 30 days.

Products to evaluate *
What you need it for
Read the terms

Confidentiality terms for the security documentation

  1. Criterium AI's security documentation is confidential information. It is shared only to evaluate Criterium AI as a provider or to manage an existing contractual relationship.
  2. It may be shared with people in your organization and with advisors who need it for that purpose and are bound by confidentiality. It may not be published, sold, or used to develop products or services that compete with Criterium AI's.
  3. Each document is shown marked with the viewer's name, company, and date. Access is personal, expires after 30 days, every view is logged, and Criterium AI may revoke it at any time.
  4. The documentation describes controls in place as of each document's review date and does not amend any contract. If your organization has already signed a confidentiality agreement or a contract with Criterium AI, that document prevails.
  5. These obligations survive for three years after the last view.

I already have access

Responsible disclosure

If you find a vulnerability, write to us.

Write to hola@criterium-ai.com with the subject Security, including the steps to reproduce the issue and the affected product. We confirm receipt within two business days and let you know when it is fixed. We take no action against good-faith research that does not access third-party data, does not degrade the service, and does not disclose the issue before it is fixed. We do not run a bounty program at this time.

hola@criterium-ai.com