Security & trust

Enterprise-grade by default. Built to clear procurement.

Enterprise data and live brand-facing experiments, protected the way your security, legal and brand teams expect. Audited, encrypted, never used to train anyone else's model.

SOC 2 Type II
Independently audited
AES-256 + TLS
At rest, in transit
GDPR
Aligned processing
US · EU · AU
Data residency
01 / Your data lifecycle

In your control at every step.

Your first-party data powers the Customer Context Layer, and stays yours. We process it to serve you, never to enrich a shared model or another customer.

  1. 01
    Ingest

    Connected over encrypted channels with scoped, least-privilege access you control and can revoke.

  2. 02
    Isolate

    Your context layer is logically isolated to your organization. AES-256 at rest, TLS in transit.

  3. 03
    Use

    Used only to generate your predictions and experiments, never to train third-party or shared models.

  4. 04
    Retain & delete

    Retention is set by your policy. Request export or deletion at any time and we honor it.

02 / Access and audit

Who can get in, and what gets logged.

SAML SSO and role-based access

Your identity provider signs people in. Roles decide what each of them can see and do.

Audit logging

Activity trails for every workspace, ready for review and export.

Scoped, revocable connections

Data sources connect with least-privilege access you control and can withdraw at any time.

03 / Brand-safe by design

Test in the open market without exposing the brand.

Lookalike brand mode runs live experiments under a lookalike brand, so you can validate bold ideas with real buyers before a single thing touches yours. For teams in regulated categories, that means testing a product concept without it reading as an announcement. Nothing ships under your name until you have seen the evidence.

A live experiment running in market under a lookalike brand

Send it to your security team.

Everything your review needs, in the form it asks for it.

Data processing addendum

Published in full. Read the DPA →

SOC 2 Type II report

Under NDA, on request.

Architecture overview

Under NDA, with the SOC 2 report.

Questionnaires and reports

Security reviews and vulnerability reports: security@heatseeker.ai

Request security docs →