Skip to main content

SECURITY

Built for scrutiny.

Security and control are not features added to Balau AI—they are the architecture. Context is permission-scoped, actions are human-controlled, and evidence is kept by default.

What follows are the answers a security questionnaire asks for: how firms are isolated, how data is encrypted, what the record keeps, what the AI sees, and how to reach us with a finding.

  • PERMISSION-SCOPED
  • HUMAN-CONTROLLED
  • EVIDENCE BY DEFAULT

Four commitments.

  1. 01

    Permission follows firm roles.

    Access is resolved from the firm’s roles and permissions at the moment of use—not maintained as a separate AI permission layer.

  2. 02

    Outputs carry their sources.

    Summaries, drafts, and answers come with references to the material behind them, ready for inspection.

  3. 03

    Consequential changes require human approval.

    Consequential changes and anything leaving the firm pass through a named human approval.

  4. 04

    Access and activity evidence is preserved.

    Who saw what, when, and what was approved—retained and reconstructable.

ARCHITECTURE

How the platform is built.

Four properties of the system, stated plainly enough to paste into a questionnaire. They describe what holds, not which products it is built from. Implementation detail belongs in the documentation pack, where a reviewer can read it under an NDA.

  • TENANT ISOLATION

    How is one firm’s data kept separate from another’s?

    Every customer firm is a separate logical tenant. Database-level Row-Level Security is enforced on every table, and the query layer requires an explicit tenant scope on every call, which Row-Level Security then enforces at the database.

  • ENCRYPTION

    How is customer data protected at rest and in transit?

    Customer data is encrypted at rest under per-tenant AES-GCM envelopes, so each tenant’s data is cryptographically bound to its own key, and in transit via TLS 1.3. Keys are managed under cloud-native key management with separation between key-encryption and data-encryption keys. Operator access to plaintext is auditable end-to-end.

  • APPEND-ONLY AUDIT LOG

    What is recorded, and can the record be changed afterwards?

    Every sensitive action (read, write, delete, AI dispatch, sub-processor routing) writes an audit record. Append-only enforcement lives at the database layer; no application-side role has permission to modify or delete rows. Audit records are retained for seven years. The firm remains the record-keeper of obligation.

  • AI DATA HANDLING

    What does the AI see, and what leaves the firm?

    Customer plaintext is redacted before any prompt leaves our perimeter: names tokenized, sensitive identifiers and signature blocks stripped, plus per-tenant pattern overrides. Redaction is enforced by the type system at compile time on the context-packet path, and at runtime on every other path that reaches a model. AI provider contracts include zero-retention commitments. The per-task model inventory and the redaction rule set are visible live in the product’s AI policy settings and are provided during procurement review.

OPERATIONS

How it is run.

Where the data sits, how long it is kept, who can reach it, who else processes it, and what happens on the day something goes wrong.

  • DATA RESIDENCY

    Where does customer data live?

    Customer data is stored and processed in the United States, and the third-party services that process it on our behalf operate in United States regions. Balau AI is a US company serving US firms, so US law is the governing regime and US state privacy law is the primary privacy framework we work to.

  • RETENTION

    How long is data kept, and can it be deleted?

    Retention is defined rather than open-ended. Audit records are retained for seven years. Retention windows for customer content, and the deletion and export paths available to a firm, are set out in the customer contract and are provided on request during review. Customer data is never used to train models.

  • ACCESS CONTROL

    Who can see a firm’s data?

    Inside the product, access is resolved from the firm’s own roles and permissions at the moment of use, so there is no second AI permission layer to configure, sync, or reconcile. Answers, summaries, and drafts are built only from material the person asking is permitted to see. On our side, access follows least privilege, and operator access to plaintext is auditable end-to-end.

  • INCIDENT RESPONSE

    What happens if something goes wrong?

    Suspected incidents are triaged on receipt, and incident response is a documented part of the security program rather than an improvised one. The append-only audit log is what makes reconstruction possible: what was accessed, by whom, and when. Affected customers are notified in line with their contract and with applicable US state breach-notification law.

    Report a suspected incident to security@balau.ai.

  • SUB-PROCESSORS

    Who else touches the data, and how would we hear about a change?

    Third-party services that process customer data on our behalf receive only the data their purpose requires, and providers of AI capability receive only redacted prompts under zero-retention commitments. The current inventory, with the purpose and processing region of each entry, is provided during procurement review and alongside the customer contract rather than published here. Customers on the change-notification list receive 30 days’ advance notice before a sub-processor is added, removed, or has a material change of scope.

    Subscribe to change notices by emailing trust@balau.ai with the subject “Subscribe to sub-processor change notices.”

PROGRAMS

Independent scrutiny,
in progress.

SOC 2 Type 2 and ISO 27001 programs are in progress. Documentation of our posture, sub-processors, and practices is available to prospective customers on request.

Request documentation

  • Encryption in transit and at rest.

  • Tenant isolation by design.

  • Least-privilege access.

  • Defined retention; data never trains models.

  • Personal identifiers redacted before AI processing.

DILIGENCE

What can you send our compliance team?

Email trust@balau.ai with the documents you need. We typically respond within five business days, with our mutual non-disclosure agreement attached for counter-signature. Everything below is released under that NDA rather than published.

  • SOC 2 Type 2 report

    Available once the first attestation completes. The SOC 2 Type 2 and ISO 27001 programs are in progress; until a report or certificate is in hand we claim neither.

  • Penetration test results

    The most recent independent security assessment, redacted for tester anonymity under the testing contract.

  • Threat models and Data Protection Impact Assessments

    Structured threat models and impact assessments for the load-bearing surfaces of the platform, including the surfaces where AI touches customer material.

  • Compliance posture snapshot

    A cross-framework review of our control posture, refreshed at minimum quarterly, so a reviewer sees the current state rather than a launch-day snapshot.

DISCLOSURE

How do I report a vulnerability?

Send the report to security@balau.ai with reproduction steps and any artifacts that help us confirm the finding. Security research is welcome here, and a finding reported in good faith is treated as a contribution rather than a nuisance.

  • INITIAL RESPONSE

    Within five business days of the report reaching us.

  • TRIAGE AND REMEDIATION

    A timeline is communicated once we have reproduced the finding, paced by severity, with critical findings prioritized same-week.

  • SAFE HARBOR

    Good-faith research conducted within the scope below is welcome. We ask that researchers do not access, modify, or exfiltrate customer data, and that they coordinate disclosure with us before publishing.

  • SCOPE

    All production surfaces under balau.ai and app.balau.ai. Out of scope: denial-of-service testing, social engineering of employees, physical attacks, and third-party sub-processors, which should be reported upstream.

CONTACT

Who should we write to?

Three inboxes, so a request reaches the right desk without a handoff.

  • Privacy

    privacy@balau.ai

    Privacy requests, CCPA and US state-privacy inquiries, and questions about our processor relationship.

  • Security

    security@balau.ai

    Vulnerability reports, suspected incidents, and security questionnaire follow-ups.

  • Trust and compliance

    trust@balau.ai

    Confidential-document requests, NDA execution, and compliance questions.