Skip to main content
Security & Trust

Encryption at every layer, a human sign-off on every risky action, and an audit trail for everything. Here is exactly how Fleece AI protects your data.

TLS 1.3AES-256 at restSOC 2 CC7-alignedGDPRCCPAEU AI Act
How we protect you

Six guarantees, not a checkbox.

Every measure below is live in production today.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest across the database and every backup. API keys are SHA-256 hashed and shown only once, at creation.

You keep the final word

Risky actions — sending money, emailing a customer, publishing — pause at an approval gate until a human clicks. Every change is versioned and reversible.

Your data never trains AI

Prompts and agent tasks go to AI providers for real-time inference only. Nothing you run is ever used to train a model.

Strict tenant isolation

Every database query is scoped by user ID. No cross-tenant access is possible, and each API key maps to a single authenticated user.

Immutable audit log

An insert-only log aligned with SOC 2 CC7 records 25+ event types — auth, data access, billing, admin — each stamped with user, resource, IP and time.

Hardened infrastructure

Vercel edge with automatic HTTPS and DDoS protection, Neon Postgres with failover and point-in-time recovery, Stripe payments under PCI DSS Level 1.

Compliance at a glance

The numbers behind the trust.

AES-256
Encryption at rest
0+
Audited event types
0 days
Full data deletion on request
99.99%
Infrastructure uptime SLA

GDPR · CCPA · EU AI Act · SOC 2 Type II (in progress) · PCI DSS Level 1 via Stripe

An AI workforce your security team will approve.

Read the full security practices, or talk to us about enterprise controls, dedicated infrastructure and custom data-retention policies.

Security Practices | Fleece AI