Security & Trust Centre
Everything a security reviewer needs to start an evaluation: who we are, how the platform is deployed, which controls exist, their current assurance status — and what is not yet done.
The responsible entity
| Legal entity | mAIb Tech LLC — a Delaware limited liability company |
| Registered address | 8 The Green, STE R, Dover, DE 19901, USA (registered-agent address) |
| General & sales contact | support@maib.io |
| Security contact | support@maib.io (subject: Security) — see responsible disclosure |
| Privacy contact | support@maib.io (subject: Privacy) — see privacy policy |
| Products | Locs (flagship), GAIO, AOS-1 — see the product directory |
| Company stage | Pre-launch · design partners onboarding · founder-led |
Controls and their current status
Status reflects the current release of the platform as built. "Implemented" means enforced in code in the product; it does not mean externally audited.
| Control | Status | Note |
|---|---|---|
| On-premises / customer-hosted deployment | Implemented | — |
| Air-gapped operation with offline signed updates | Implemented | — |
| Zero raw-data egress by design | Implemented | Design property, verifiable at the customer network boundary |
| Third-party penetration test | Planned | No report exists yet; none is claimed |
| Control | Status | Note |
|---|---|---|
| OIDC enterprise identity (Entra profile) | Implemented | — |
| RBAC enforced in retrieval queries | Implemented | — |
| ACL preservation from source systems (fail-closed) | Implemented | — |
| Support access off by default; time-limited, audited sessions | Implemented | — |
| Control | Status | Note |
|---|---|---|
| Deterministic secret blocking at ingestion | Implemented | — |
| Redaction before embedding | Implemented | — |
| Human approval before knowledge activation | Implemented | — |
| Golden-set evaluation before operational use | Implemented | — |
| Regression evaluation after model/knowledge changes | Implemented | — |
| Control | Status | Note |
|---|---|---|
| Append-only hash-chained audit trail | Implemented | Tamper-evident, not WORM |
| SIEM forwarding of security events | Implemented | — |
| Kill switch with deployment drill | Implemented | — |
| Encrypted backups with verified restore drills | Implemented | — |
| Control | Status | Note |
|---|---|---|
| ISO/IEC 27001, ISO/IEC 42001, SOC 2 | Roadmap | No issued certification claimed |
| Framework alignment mappings (EU AI Act, NIST AI RMF) | Under review | — |
| Public status page | Owner-gated | Published only when a real status system is operational |
mAIb Tech does not claim an issued certification unless explicitly stated. No penetration-test report, SOC 2 report or ISO certificate currently exists for this platform; language on this site is written so that nothing implies otherwise.
Documentation for evaluators
Documents are provided through a request so we can version-control what evaluators receive. Nothing here is a fake download: each state below is the real, current state.
Security overview
Available on requestArchitecture overview
Available on requestData-flow overview
Available on requestDeployment models & shared responsibility
Available on requestThreat model
Available under NDAPrivacy overview
Available on requestAI-governance overview
Available on requestFramework-alignment overview
In preparationIncident-response overview
In preparationData handling on this website
The product runs in customer environments and handles no customer data on our infrastructure. This website collects only what visitors submit through forms (handled per the privacy policy) — see subprocessors for the services involved in running the site itself.