Trust and Security

At Fisent, safe and secure use of AI is paramount. We employ enterprise grade data security policies with the help of Vanta and Dansa D’Arata Soucia as our compliance partners.

SOC 2 Type II

We’re SOC 2 Type 2 compliant.
Request reports here.

red-sentry-70x70

RedSentry

Penetration test completed
on 10-08-2024.

DansaDarataSoucia-Logo-Color-tag-e1614805778997-90x90

Dansa D’arata Soucia

Performed a SOC 2 Type 2
examination.

Trusted by Enterprises Globally

Best-in-Class Security practices

  • Zero Retention:

    Client data processed through BizAI is never retained or used for training. Fisent ensures this policy applies to our own APIs and with our enterprise agreements with any third party model hosts.

  • Encryption:

    All data at rest is secured using AES-256 encryption, with data in transit is encrypted using HTTPS (TLS 1.2/1.3).

  • Accuracy Tracking:

    Our GenAI Efficacy Framework (GEF) allows clients to track output accuracy and ensure internal standards are met prior to and following deployment.

  • Employee Education:

    All our employees receive routine security awareness training, creating a culture of security consciousness.

  • Access Controls:

    Fisent employs a strict policy of least-privilege access to systems and data, which includes the use of strong MFA. BizAI’s codebase leverages infrastructure-as-code to ensure fine-grained permissions are granted to services and components defined within the architecture. Network activity and system access is continuously monitored with alarms to alert on suspicious events.

  • Regular Audits:

    Fisent’s compliance partners conduct regular security audits and penetration tests to identify and address any vulnerabilities.

  • Continuous Compliance:

    Through Fisent’s partnership with Vanta, security controls are monitored in real-time and adapt as compliance frameworks evolve. Fisent’s Trust Center enables customers a real-time view of controls, and a central place to view all compliance documentation.

Your data remains your own.
Our solutions do not train or retain client data.

Want to Dive Deeper?