Trust & Security

How Binary AIP keeps enterprise AI safe.

This page is maintained by Binary AIP to answer common security, privacy and compliance questions about the platform. It describes enabled controls and current practices — it is not an independent certification. For a Data Processing Agreement, subprocessor list or your security questionnaire, please contact us.

Shared responsibility

What Binary AIP secures vs. what your team configures.

Binary AIP responsibility

Platform security, application hardening, encryption, audit logging, isolation between customers, secure SDLC for the product.

Customer responsibility

Identity provider configuration, user lifecycle, role assignments, DLP policy choices, data classification, approval workflows, model and runtime selection.

Joint responsibility

Incident response coordination, change management for major releases, periodic access reviews and policy reviews.

Platform controls in place today

Enabled controls and current practices. Disabled controls and remediation details are not shown here — those are available under NDA on request.

Identity & Access

  • Single Sign-On with Microsoft Entra ID and Google Workspace (configurable).
  • Multi-Factor Authentication enforced via the chosen identity provider.
  • Role-Based Access Control with separation between Builder, Approver and Deployer roles.
  • Department / Business Unit scoping for least-privilege access.

Data Collection & Use

  • Only the data your administrators submit through the assessment, discovery and configuration workflows is processed.
  • Enterprise-confidential data is not sent to public LLMs without explicit configuration and approval by your team.
  • Prompts flagged by DLP detectors can be blocked, masked or routed for approval based on your policy.

Hosting & Residency

  • Default hosting region is configurable. India-first residency is supported for DPDP-aligned deployments.
  • Private cloud, hybrid, on-premises and air-gapped deployment patterns are available for sensitive workloads.
  • Runtime selection is recommended per data classification — Public, Internal, Confidential, Restricted, Highly Restricted.

Encryption

  • Data is encrypted in transit using TLS.
  • Data at rest is encrypted by the underlying platform storage provider.
  • Customer-managed keys are available for Enterprise and Sovereign deployment tiers (please contact us to enable).

Audit & Logging

  • Administrative actions, approvals and policy changes are recorded in an immutable audit log.
  • Prompt-scanning decisions (block / mask / approve / allow) are logged with user, timestamp and detector.
  • Audit logs are exportable for review by your internal Security and Compliance functions.

Retention & Deletion

  • Data retention windows are configured during onboarding and documented in your subscription agreement.
  • On termination, customer data is deleted in line with the contract; certified deletion can be requested.
  • Customers can request export of their data prior to deletion.

Compliance posture

Binary AIP does not currently claim certification under SOC 2, ISO 27001 or ISO 42001. The status below reflects the path we are on. We will publish certificates here once issued by accredited auditors.

DPDP (India) alignment
In progress
ISO 27001 (Information Security)
Planned
ISO 42001 (AI Management System)
Planned
SOC 2 Type I / Type II
Planned
Annual VAPT (third-party)
Planned
DPIA / Data Protection Impact Assessment templates
Available on request

Security incident contact

If you believe you are experiencing a security incident involving Binary AIP, contact us at security@binaryaiq.com. Incident notification timelines are defined in your subscription agreement.

Responsible disclosure

Researchers can report vulnerabilities to security@binaryaiq.com. Please give us reasonable time to investigate and remediate before public disclosure. We do not pursue good-faith researchers who follow this policy.

Need a DPA, subprocessor list or security questionnaire?

We share these under NDA with qualified buyers.