Security

What we protect, how we operate and what we do not claim

Security requirements are defined for each implementation because the data, vendors and risk are different for every workflow.

Client ownership

Client repositories, domains, servers and third-party accounts are created in the client's name and the client receives administrative access.

Encrypted transport

The public Structured by AI site is served over HTTPS with HTTP Strict Transport Security enabled.

Secret handling

Provider credentials and signing secrets are configured on the server and are not intentionally exposed in browser code.

Scoped integrations

Connections are designed around the permissions required for the approved workflow instead of assuming unrestricted access.

Auditability

Customer-facing AI workflows are designed to retain the context needed to review actions, failures and escalation decisions.

Human escalation

High-consequence, ambiguous or unsupported requests are routed to a person rather than treated as safely autonomous.

Current certification status

Structured by AI does not currently claim SOC 2 certification, ISO 27001 certification or blanket HIPAA compliance. A regulated deployment requires a separately reviewed architecture, vendor chain, contracts, retention policy and operating procedure.

A logo or infrastructure feature alone does not make a complete workflow compliant.

Report a security issue

Send a concise description, affected URL or component and reproduction details to support@structuredbyai.com.

Do not include personal data, production credentials or destructive proof. We will acknowledge a good-faith report and coordinate validation and remediation.