GoFactAI

Security Model

Your data is your data

Fact AI Lab is designed for regulated industries where data handling is non-negotiable. The platform processes your LLM outputs to verify them. It does not store, train on, or share them.

Data residency

  • Your data never leaves your designated cloud region without explicit configuration.
  • Audit logs are written to your S3-compatible storage, not ours.
  • There is no cross-customer data access - single-tenant log storage by default.
  • Data processing region is configurable: US, EU, CA.

In-transit and at-rest

  • All API traffic is encrypted in transit with TLS 1.3.
  • Audit logs are encrypted at rest with AES-256.
  • Log entries are hash-chained: any tampering is detectable.
  • Cryptographic signatures on each log entry use ECDSA-P256.

Data retention

  • Raw prompts are retained for 24 hours in the processing buffer, then purged.
  • You control audit log retention - we do not impose a limit.
  • Configurable retention policies are available for different workflow types.
  • Deletion requests are honored within 24 hours.

Access controls

  • API key rotation is available on-demand, with no support ticket required.
  • Webhook signature verification applies to all outbound events.
  • IP allowlisting is available for API access.
  • Detailed access logs are available for your own SIEM.

Certifications and compliance status

Fact AI Lab is a pre-Series A company. We do not yet hold SOC 2 Type II certification. We are designed with SOC 2 principles in mind and will pursue certification when our customer base requires it.

Our audit report templates are structured for SEC AI governance guidance (2023 and 2024 staff bulletins), FINRA's AI examination framework, FCA's Consumer Duty and AI principles, and OSFI's B-10 guidelines. HIPAA audit requirements are also supported.

We do not certify your compliance - that is your counsel's job - but we provide the documentation package they need.

Contact

For security questions, contact security@gofactai.com.