Security at SecureAI Guard
How to reach us about a vulnerability, and how the product is built to limit what it can see.
Reporting a vulnerability
Email security@secureaiguard.com with enough detail to reproduce the issue — the affected endpoint or page, the steps, and what you observed. If you have a proof of concept, include it.
We will acknowledge your report, keep you informed while we investigate, and credit you publicly if you would like to be credited.
We will not pursue legal action against anyone who reports a vulnerability in good faith, gives us a reasonable opportunity to fix it before disclosing it publicly, and does not access, modify or delete data belonging to other people while researching it. Please do not run automated scanning that degrades the service for anyone else, and do not test with real customer data.
What this product can see
SecureAI Guard inspects the traffic between an application and the models it calls. Inspection means it necessarily processes the content of prompts and completions, including whatever the application put in them — retrieved documents, conversation history, tool definitions and tool results. There is no version of this product that does its job without seeing that content, and a vendor in this category that implies otherwise is describing something else.
Three design properties follow from that, and they are the ones worth checking in any security layer you evaluate, ours included:
- It runs server-side.
A control that runs in the client is advice, not enforcement — the client can be modified and the model endpoint called directly.
- It inspects both directions.
Input-side inspection alone cannot enforce output handling, and the output side is where a successful attack becomes visible.
- It can run without sending content outside your network.
For workloads that cannot tolerate prompt content leaving their boundary, see on-premises deployment.
Retention, residency, subprocessors and compliance
Those answers belong in one place with dates against them, and that place is the trust page. It covers what is retained and for how long, whether customer content is ever used for training, which regions process it, who our subprocessors are, and our position on SOC 2, ISO/IEC 27001 and ISO/IEC 42001 — stated plainly, including where the honest answer today is "not yet".
We would rather publish that page with visible gaps than publish a certification we do not hold. If a specific answer is blocking a review on your side, email security@secureaiguard.com and we will tell you where we actually are.
Requesting a DPA or a security questionnaire
Email security@secureaiguard.com or use the contact form. Send us your own questionnaire rather than waiting for a template — it is faster, and it tells us which controls your review actually turns on.
Security guidance for the systems you are protecting
Separately from our own posture, we publish what we know about securing LLM applications in general: