Security & Compliance

Your code. Your memory. Your rules.

AI employees with real access need real boundaries: least privilege, a human on anything sharp, and a log of everything.

The principle

Automation should increase trust, not spend it.

Least privilege, always

An employee reaches only what its role needs. Nothing else exists to it.

A human on the sharp edges

Production, security, infrastructure — it stops and waits for a person.

Everything is recorded

Every action, approval and refusal logged — “why did it do that” always has an answer.

Human control

Where the line sits.

Not a setting you switch on. It is how the product works.

AI executes

  • Read code, tickets, docs and past incidents
  • Investigate, plan and write changes
  • Run tests and CI pipelines
  • Open pull requests for review
  • Deploy to non-production environments
  • Draft updates, summaries and postmortems

Humans approve

  • Production deployments
  • Security-sensitive changes
  • Infrastructure changes
  • Customer-facing messages
  • Granting an employee new system access
  • Anything outside an employee’s defined role

Approval is a record, not a click

The request, the diff, the reasoning, the approver and the decision — captured together, ready for the auditor’s favourite question.

Platform

The controls under every plan.

Including the free one.

Encryption in transit

TLS 1.2+ everywhere, HTTPS-only with HSTS.

Encryption at rest

AES-256 on every store that holds your code or memory.

Per-tenant isolation

Your memory is yours alone. Every request authorized against your tenant.

SSO and SAML

Google, Microsoft, Apple or enterprise SAML — lifecycle stays in your IdP.

Role-based access control

Owner, Admin and Developer govern who hires, grants and approves.

Secrets stay out of memory

Credentials live in a broker, never in an employee’s memory. It can’t leak what it doesn’t hold.

Full audit trail

Every action logged, attributable, reviewable end to end.

Hardened infrastructure

AWS, managed Postgres, private networking, stateless services.

Private deployment

On Enterprise: your cloud account, your infrastructure, your model.

Your data

What we do with what you give us.

We don’t train on your code

Your code and memory do your work — never train shared models, never pool with another customer. Your knowledge staying yours is the whole product.

Your memory belongs to you

Inspect it, correct it, take it with you. It follows you between plans and doesn’t evaporate if you leave.

Model providers are configurable

Multiple LLM providers; Enterprise brings its own model or endpoint. Which third party sees a prompt is a choice you make.

Data residency and deletion

Tell us your requirements and we’ll answer plainly. Deletion: see the Privacy Policy or write to us.

Compliance

Where we actually stand.

Standards & compliance

  • SOC 2 Type IIIn progress
  • ISO 27001In progress
  • GDPRAligned
  • HIPAAReady
  • AWS InfrastructureSOC 2 / ISO 27001 certified

“In progress” means not yet certified — we won’t call it anything else until an auditor does. The AWS infrastructure underneath is certified; that’s a different claim, kept separate on purpose. Ask us for current status and documentation.

Subprocessors

Who else touches the data.

Kept current. We tell you before it materially changes.

EdgeX11 subprocessors
ProviderPurposeApplies to
Amazon Web ServicesHosting, compute, managed database, object storage and content deliveryWebsite and product
LLM providersModel inference for AI employees. Configurable per organization; Enterprise can bring its own model or endpoint.Product
StripePayment processing for paid plans. Card details go to Stripe, never to us.Product (paid plans)
Web3FormsDelivers website contact form submissions to our inboxWebsite
Google AnalyticsWebsite usage measurement, loaded only after you accept cookiesWebsite

Scroll the table sideways on a narrow screen.

This website

Even the brochure is locked down.

The cheapest possible signal of whether a vendor bothers.

HTTPS only + HSTSStrict CSP, served as a headerClickjacking & MIME-sniff protectionNo trackers, no ad cookiesStatic hosting — no app to breach

Responsible disclosure

Found something? Tell us.

  1. Email us

    admin@edgex11.com, “Security” in the subject, steps to reproduce.

  2. We acknowledge

    Within two business days, with updates until it’s fixed.

  3. We fix, then you publish

    Give us reasonable time to remediate; we’ll credit you if you’d like.

  4. Ground rules

    Only your own data, no service degradation, no social engineering. Good-faith testing is welcome.

Security FAQ

The questions reviews always ask.

Do you train models on our code?

No. Your code, documents and organizational memory are used to do your work, not to train shared or third-party models, and they are never pooled with another customer’s data. Your memory is isolated to your tenant.

Can an AI employee deploy to production by itself?

No. Production deployments, security-sensitive changes, infrastructure changes and customer-facing messages all require explicit human approval. The employee prepares the change and asks; a person decides. Both the request and the decision are recorded.

What access does an employee actually have?

Only what you grant, scoped to its role, least-privilege by default. Credentials are held in a broker rather than stored in the employee’s memory, so its memory cannot leak a secret even in principle.

Are you SOC 2 or ISO 27001 certified?

Not yet — both programs are in progress, and we would rather tell you that than imply otherwise. EdgeX11 runs on AWS infrastructure that is itself SOC 2 and ISO 27001 certified, and our practices are GDPR-aligned. Contact us for current documentation and status.

Can we run EdgeX11 inside our own cloud?

Yes, on Enterprise. Private deployment puts EdgeX11 in your own account on dedicated infrastructure, with the option to bring your own model, so neither code nor memory leaves your environment.

How is one customer’s data separated from another’s?

Every organization is a distinct tenant. Operational data and the organizational memory are isolated per tenant, and every request is authorized against the tenant it belongs to. There is no shared memory between customers.

How do we report a vulnerability?

Email admin@edgex11.comwith “Security” in the subject. We aim to acknowledge within two business days. See responsible disclosure above for the ground rules.

Next step

Send this page to your security reviewer.

Then ask us for whatever it doesn’t cover.

No credit card required. Nothing ships without your approval.