Trust & Security

Enterprise-grade by default.

Every answer enterprise procurement asks for — already documented.

SOC 2 Type I In progress

Target: Q4 2026 · Auditor: to be named

Revenue-first roadmap. Enterprise buyers: we'll share our audit timeline and controls summary under NDA via dev@remlabs.ai.

SOC 2 Type II Roadmap

Target: Q2 2027 (planned, follows Type I)

GDPR DPA Available now

Request DPA

HIPAA BAA Available on Enterprise

Request BAA

  • Encryption at rest: AES-256 (key rotation: 90 days).
  • Encryption in transit: TLS 1.3 (HSTS preload).
  • Hard delete with cryptographic proof (GDPR forget()).
  • Zero-retention mode (opt-in per namespace).
  • PII detection + redaction at ingest (configurable).
  • BYOK (bring your own key) — AWS KMS / GCP KMS / Azure Key Vault (Enterprise).
Vendor Purpose Region DPA
Anthropic LLM inference (Dream Engine) US Yes
OpenAI Embeddings US Yes
Railway Compute / background workers US Yes
Supabase Primary memory database (Postgres + pgvector) US (us-east-1) Yes
Cloudflare CDN / WAF Global Yes
Vercel Frontend hosting / marketing site Global edge Yes
Stripe Billing US Yes
Google OAuth 2.0 (console login only) Global Yes

Updated 2026-04-26. Authoritative source: /compliance.json. Subscribe to change notifications via dev@remlabs.ai.

Responsible disclosure rewarded. Scope: remlabs.ai, console.remlabs.ai, api.remlabs.ai. Report to dev@remlabs.ai. PGP key on /.well-known/security.txt.

We publish post-mortems within 5 business days for any SEV-1.