Skip to main content
Institutional Governance & Security Assurance

Compliance & Security Standards

Certainium is engineered for asset-heavy enterprises, private equity sponsors, and financial institutions where data confidentiality, regulatory auditability, and mathematical fidelity are non-negotiable.

SOC 2 Type II Alignment

Our operational controls, logical access frameworks, continuous vulnerability assessments, and change management procedures are designed to meet SOC 2 Type II trust criteria for Security, Availability, and Confidentiality.

  • Role-based access control (RBAC) & SAML 2.0 / Okta SSO integration
  • Immutable audit logging of all parameter alterations and simulation executions
  • Annual third-party penetration testing and automated vulnerability scanning

Zero Data & Model Retention Guarantee

Your proprietary strategic hypotheses, margin sensitivities, and debt covenants never leave your operational boundary. We enforce contractual guarantees ensuring customer data is never used to train public or shared foundation models.

  • Zero training on customer inputs or Monte Carlo trial scenarios
  • Ephemeral execution containers purged immediately following simulation batches
  • Remote FastMCP protocol returns statistical distributions rather than raw model source

Dedicated Single-Tenant Enclaves

Enterprise tier customers can deploy Certainium within single-tenant, isolated virtual private cloud (VPC) instances on Google Cloud Platform or Amazon Web Services with dedicated compute clusters.

  • Private network interconnects with AWS Direct Connect or GCP Cloud Interconnect
  • Complete hardware and storage isolation from multi-tenant workloads
  • Dedicated IP ranges and strict egress filtering policies

Encryption & Key Management

All data in flight and at rest is secured using modern cryptographic standards, with full support for customer-managed keys (CMEK) via cloud HSM services.

  • TLS 1.3 encryption with strict forward secrecy for all web and API communication
  • AES-256 encryption for database volumes, backups, and artifact storage
  • Optional Customer-Managed Encryption Keys (AWS KMS / GCP Cloud KMS)

Need a Vendor Security Assessment or Due Diligence Dossier?

Our security engineering team assists enterprise procurement, risk committees, and architecture review boards with detailed security questionnaires and architectural reviews.

View Enterprise Architecture