Encryption
TLS 1.2+ in transit, AES-256 at rest, with customer-managed keys available on Enterprise. Credentials are stored in your vault, not ours.
Home / Security
Security & trust
Giving software the ability to read your systems and change records raises the stakes on every control around it. Ayoopa is built so that the security answer is a configuration, not an exception.
TLS 1.2+ in transit, AES-256 at rest, with customer-managed keys available on Enterprise. Credentials are stored in your vault, not ours.
SAML and OIDC SSO, SCIM provisioning, scoped service accounts and per-agent permissions. Least privilege is the default, not an option.
An immutable record of prompts, tool calls, approvals and configuration changes, exportable to your SIEM or storage on a schedule you control.
Run in your own cloud account, on-premise or in an air-gapped network. Workloads are isolated per workspace with no shared execution path.
Regional residency, configurable retention, PII redaction before logs are written, and a contractual guarantee that your data never trains a model.
Independent penetration tests, a documented incident response process, and a security contact that answers. Status and advisories published to customers.
Controls
| Area | Control |
|---|---|
| Certification | SOC 2 Type II, audited annually by an independent firm. Report available under NDA. |
| Encryption | TLS 1.2+ in transit; AES-256 at rest; optional customer-managed keys. |
| Authentication | SAML 2.0 and OIDC SSO, SCIM 2.0 provisioning, enforced MFA for local accounts. |
| Authorization | Role-based access control, per-agent scopes, approval gates on sensitive actions. |
| Logging | Immutable audit trail, configurable retention, scheduled export, SIEM integration. |
| Residency | US, EU or your own infrastructure. Data stays in the region you select. |
| Model training | Customer data is never used to train or fine-tune models, by Ayoopa or its providers. |
| Testing | Annual third-party penetration test and continuous dependency scanning. |
Disclosure
We welcome reports from security researchers. Send a description and, where possible, a reproduction to the address below. We aim to acknowledge within two business days and will keep you updated through remediation.
Please do not test against customer workspaces, run denial-of-service tests, or access data that is not yours.
Procurement