Skip to content

Trust Center

Trust, engineered in.

Every capture, document, and model weight on this platform belongs to one customer and stays with that customer. This page states what we hold, how it is protected, who has audited it, and what happens when something breaks. Reports, model cards, and DPAs go to your reviewers under NDA.

Attestation
SOC 2 TYPE II
ISMS
ISO/IEC 27001:2022
Uptime, trailing 12 mo
99.95%
Encryption
TLS 1.3 · AES-256
How the Brain is isolatedTRUST · SOC 2 TYPE II · ISO 27001:2022
AUDIT · ANNUAL · REPORTS UNDER NDA

Certifications & attestations

Audited, not asserted.

Independent auditors test these controls on a fixed cadence, and the report names them. Scope, observation window, and audit dates are stated below; the evidence behind each one goes to your reviewers on request.

Hover, focus, or tap a tile — each one turns over to what the standard means for you.

  • STATUS · CURRENT · 2026-03

    SOC 2 Type II

    Security, availability, and confidentiality criteria tested over a rolling twelve-month observation window by an independent US audit firm.

    • SCOPE · PLATFORM · CAPTURE · AI SERVICES
    • WINDOW · 12 MONTHS ROLLING
    • REPORT · ON REQUEST · NDA
    WHAT THIS MEANS FOR YOU

    SOC 2 Type II

    An independent auditor tested the controls over your data for a full year rather than a single day, and your reviewers can read the report under NDA before you sign anything.

    EVIDENCE · FULL REPORT · UNDER NDA
  • STATUS · CERTIFIED · 2025-11

    ISO/IEC 27001:2022

    Information security management system certified against the 2022 revision, with the Statement of Applicability issued alongside the certificate.

    • SCOPE · ALL PRODUCTION SERVICES
    • SURVEILLANCE · ANNUAL · NEXT 2026-11
    • SOA · ISSUED WITH CERTIFICATE
    WHAT THIS MEANS FOR YOU

    ISO/IEC 27001:2022

    Security here is a managed system with named owners and an outside check every year, so your questionnaire gets a certificate and a written scope instead of a promise.

    EVIDENCE · CERTIFICATE · SOA
  • STATUS · ALIGNED · DPA READY

    GDPR

    Data processing agreement, standard contractual clauses for transfers, an appointed EU representative, and subject requests answered inside thirty days.

    • ROLE · PROCESSOR · CONTROLLER ON REQUEST
    • TRANSFERS · SCC · EU DATA STAYS IN EU
    • DSR · ANSWERED ≤ 30 DAYS
    WHAT THIS MEANS FOR YOU

    GDPR

    Your European data stays in Europe, the processing agreement is ready to sign, and when someone asks what you hold on them you have an answer inside thirty days.

    EVIDENCE · DPA · SCC · EU REP
  • STATUS · ALIGNED · HIGH-RISK CONTROLS

    EU AI Act

    Training sources documented per tenant, deployments risk-classified, human oversight required at every consequential step, model cards published per release.

    • CLASSIFICATION · PER DEPLOYMENT
    • OVERSIGHT · NAMED APPROVER REQUIRED
    • MODEL CARD · EVERY RELEASE
    WHAT THIS MEANS FOR YOU

    EU AI Act

    Every deployment is risk-classified and documented, and a named person signs anything consequential — so the Brain can be explained to a regulator, not only to your board.

    EVIDENCE · MODEL CARD · RISK CLASS
  • STATUS · ALIGNED · NO SALE

    CCPA / CPRA

    Personal information is never sold or shared for cross-context advertising. Access, correction, and deletion requests are served inside the statutory window.

    • SALE · NONE · SHARING NONE
    • REQUESTS · ≤ 45 DAYS
    • RETENTION · CONTRACT TERM
    WHAT THIS MEANS FOR YOU

    CCPA / CPRA

    We never sell your data or hand it to advertisers, and anyone in California — your staff or your client's — can have theirs pulled or deleted inside forty-five days.

    EVIDENCE · PRIVACY NOTICE · DSR LOG
  • STATUS · AVAILABLE · ALL TIERS

    SSO / SAML

    SAML 2.0 and OIDC against your identity provider, SCIM provisioning and deprovisioning, enforced multi-factor, and session policy set by your administrators.

    • PROTOCOL · SAML 2.0 · OIDC
    • PROVISIONING · SCIM 2.0 · JIT
    • MFA · ENFORCED · SESSION POLICY YOURS
    WHAT THIS MEANS FOR YOU

    SSO / SAML

    Your identity provider stays the source of truth, so the superintendent you offboarded on Friday cannot open a single drawing here on Monday morning.

    EVIDENCE · IDP METADATA · SCIM LOG
MODEL · 1 PER TENANT · POOLING NONE

AI governance

Your model. Your weights. Your audit trail.

The Enterprise AI Brain is one network per organization, not one model with a filter in front of it. Every control below is enforced by the platform and visible in the record — a policy document cannot separate two customers, so architecture does.

  1. 01 / 06

    Model isolation per customer

    Each organization runs its own network: separate weights, separate vector index, separate inference endpoint, separate encryption keys. There is no shared layer to leak through — not a base fine-tune, not a common embedding store, not a pooled cache. Isolation is enforced by the tenancy boundary in the platform, not by a filter in front of a shared model.

    ISOLATION · WEIGHTS · INDEX · KEYS
  2. 02 / 06

    No training across customers

    Your captures, documents, and outcomes train your model and nothing else. No pooled corpus, no shared gradients, no aggregated fine-tune, and no exception written into an addendum. The reverse holds too: no other organization has ever contributed a parameter to your network.

    POOLING · NONE · CONTRACTUAL
  3. 03 / 06

    Every inference logged

    Prompt, answer, model build, role profile, cited documents, and the person who asked are written to an append-only log at the moment of inference. Retained for the life of the contract, exportable as JSON or Parquet, and queryable by job, by role, or by date so you can reconstruct what the Brain said in March and what it read to say it.

    LOG · APPEND-ONLY · JSON · PARQUET
  4. 04 / 06

    Human sign-off gates

    Consequential actions — a progress claim, a change order, a bid submission, an incident classification — do not move on a model output. The Brain drafts with citations; a named approver signs, and the approval is part of the same record. Gates are configured per organization and cannot be disabled by the model.

    GATES · NAMED APPROVER · 4 CLASSES
  5. 05 / 06

    Data residency you choose

    Pick the region where the record lives, where inference runs, and where nightly training runs: United States, European Union, Australia, or India. Storage, processing, backups, and support tooling stay inside the region you picked, and the choice is stated in the contract rather than configured after the fact.

    RESIDENCY · US · EU · AU · IN
  6. 06 / 06

    Encryption in transit and at rest

    TLS 1.3 on every connection including capture upload from the dock, AES-256 at rest across the object store, the database, and the model artifacts. Keys sit in an HSM-backed store with ninety-day rotation, and customer-managed keys are available on the Organization tier.

    TLS 1.3 · AES-256 · BYOK · 90D

What the log holds

The log is not a summary of what the Brain did. It is the record itself: the question as it was asked, the build of the model that answered, every document the answer cited, and whether a person signed it off. Your security team can query it, your auditors can export it, and nobody at GroundReality can edit it.

How the Brain is trainedAUDIT · 100% · RETENTION YOURS

Inference audit record

RECORD · 1 OF 4.2M · APPEND-ONLY
Timestamp
2026-03-11T02:41:09Z
Tenant
MERIDIAN-BUILD-GROUP · REGION EU-WEST-1
Actor
J. OKONKWO · PROFILE 04 / 27 · SUPERINTENDENT
Question
DOES THE LEVEL 14 POUR HOLD IF REBAR SLIPS TO THURSDAY?
Model
ORG-1.4B · BUILD 2026.03.10-N · WEIGHTS TENANT-ONLY
Cited
LOOKAHEAD WK34 · DAILY LOG 03-10 · RFI-0047 · DRAWING A-401 REV C
Disposition
DRAFT · SIGN-OFF REQUIRED · APPROVER UNSET
Retention
CONTRACT TERM · EXPORT JSON · PARQUET
UPTIME · 99.95% · RTO 4H

Platform controls

The controls, in full.

Reality capture is heavy data and construction records outlive the projects they document, so the platform is built to keep both for years and hand them back intact. These are the answers your questionnaire is going to ask for.

99.95%

Uptime, trailing 12 months

4 h

Recovery time objective

15 min

Recovery point objective

Platform security controls, how each one is implemented, and the evidence available to reviewers.
ControlImplementationEvidence
IdentitySAML 2.0 and OIDC against your identity provider, SCIM provisioning and deprovisioning, enforced multi-factor, permissions scoped to the object rather than the module.SOC 2 · CC6.1 · CC6.2
EncryptionTLS 1.3 in transit including dock and robot upload, AES-256 at rest across object store, database, and model artifacts. HSM-backed keys, 90-day rotation, customer-managed keys on request.SOC 2 · CC6.7 · BYOK POLICY
NetworkPrivate subnets with no public database endpoints, WAF and DDoS mitigation at the edge, egress allowlists per environment, and administrative access only through short-lived brokered sessions.PEN TEST · 2026-02 · ANNUAL
Monitoring24/7 security operations, SIEM across platform and AI services, alerting on anomalous access and model use, third-party penetration test annually, and a paid bug bounty open year-round.SOC 2 · CC7.2 · BOUNTY LIVE
ResilienceMulti-zone deployment per region, point-in-time recovery, backups restored on a quarterly test rather than a promise, and a full disaster-recovery exercise run once a year with the results shared.RTO 4H · RPO 15MIN · DR 2026-01
PersonnelBackground checks before start, security training on joining and annually after, least-privilege access reviewed each quarter, and production access revoked within four hours of departure.ACCESS REVIEW · QUARTERLY
VendorsEvery subprocessor is reviewed before it touches customer data, listed with the data it processes and the region it runs in, and changed only after thirty days written notice to you.SUBPROCESSORS · NOTICE 30D
DISCLOSURE · ACK 1 BUS. DAY · SAFE HARBOUR

Disclosure & suppliers

Tell us what we missed.

Security work is public work. Here is how to reach the people who fix things, who we depend on to run the platform, and which documents we will send your reviewers before a contract exists.

ACK · 1 BUS. DAY · TRIAGE 3 DAYS

Responsible disclosure

Report a vulnerability to our security team directly. We acknowledge inside one business day, triage inside three, and keep you on the thread until it is closed. Good-faith research against your own tenant has safe harbour, and we credit any researcher who wants to be named.

security@groundreality.ai

NOTICE · 30 DAYS · REGION LISTED

Subprocessors

Every subprocessor is listed with the data it processes, the region it runs in, and the reason it exists. We give thirty days written notice before adding or changing one, so your review happens before the change, not after it.

Request the current list

SET · 8 DOCUMENTS · UNDER NDA

Document set

SOC 2 Type II report, ISO 27001 certificate and Statement of Applicability, penetration-test summary, architecture and data-flow diagrams, model cards, DPA and SCCs. Sent under NDA, usually the same day your reviewers ask.

trust@groundreality.ai

CONTACT · SALES · REPLY 1 BUS. DAY

Bring your security team.

We will walk your reviewers through the controls, hand over the report set under NDA, and show them exactly where your tenant begins and ends.