What we protect, how we operate and what we do not claim
Security requirements are defined for each implementation because the data, vendors and risk are different for every workflow.
Client ownership
Client repositories, domains, servers and third-party accounts are created in the client's name and the client receives administrative access.
Encrypted transport
The public Structured by AI site is served over HTTPS with HTTP Strict Transport Security enabled.
Secret handling
Provider credentials and signing secrets are configured on the server and are not intentionally exposed in browser code.
Scoped integrations
Connections are designed around the permissions required for the approved workflow instead of assuming unrestricted access.
Auditability
Customer-facing AI workflows are designed to retain the context needed to review actions, failures and escalation decisions.
Human escalation
High-consequence, ambiguous or unsupported requests are routed to a person rather than treated as safely autonomous.
Current certification status
Structured by AI does not currently claim SOC 2 certification, ISO 27001 certification or blanket HIPAA compliance. A regulated deployment requires a separately reviewed architecture, vendor chain, contracts, retention policy and operating procedure.
A logo or infrastructure feature alone does not make a complete workflow compliant.
Report a security issue
Send a concise description, affected URL or component and reproduction details to support@structuredbyai.com.
Do not include personal data, production credentials or destructive proof. We will acknowledge a good-faith report and coordinate validation and remediation.