Security

Enterprise-ready from day one.

SOC 2 Type II, ISO 42001, per-tenant encryption, optional VPC deployment and the option to bring your own model keys. We treat your code and design data like it's our own.

SOC 2
Type II report available under NDA.
ISO 42001
AI management system certified.
GDPR
EU data residency available.
HIPAA
BAA available on Enterprise.
Architecture

Tenant isolation at compute, data and model.

Data

Per-tenant KMS keys

Every workspace's data is encrypted with a dedicated key. Bring your own for Enterprise.

Compute

Isolated inference

Customer prompts never leave your tenant. No cross-customer training.

Model

Fine-tune isolation

Customer fine-tunes are tenant-scoped and never inferred outside the workspace.

Net

Private link

AWS PrivateLink and Azure Private Endpoint available.

Code

Repo access

OAuth-scoped to specific repos. We don't request what we don't need.

Logs

Immutable audit trail

Every agent action logged with cryptographic chain-of-custody.

Governance

Built for the procurement review.

DPA & SCCs

Pre-signed DPA, EU Standard Contractual Clauses, and AI Addendum on request.

Pen tests

Annual third-party pen tests. Reports available under NDA.

Bug bounty

Public program on HackerOne with up to $25k bounty.

Vulnerability disclosure

security@pixicode.com · 24-hr acknowledgment SLA.

Subprocessor list

Maintained publicly with 30-day notice on additions.

Status page

Real-time uptime and incident history at status.pixicode.com.

Security questionnaire

We've already answered yours.

CAIQ, SIG Lite and a 320-question internal questionnaire ready in the Trust Center.

Request the Trust Center