DataFab //  artificial proprietary intelligence T+00:00:00 ISO/IEC 27001:2022 · SOC 2 Type II — certified Raw egress  0 B 

DataFab  /  Trust Center

Security, compliance & assurance

The evidence, and how to obtain it.

DataFab is certified to ISO/IEC 27001:2022 and SOC 2 Type II. The architecture and governance model are described in full on this site. The certification reports, the technical dossier and access to a working system are available under NDA.

ISO/IEC 27001:2022 certifiedSOC 2 Type II certifiedDocuments and system access under NDA

Certifications

Two certifications, both maintained.

Independently assessed, and kept current under continuing surveillance rather than achieved once. Certificates and reports are released under NDA.

Information security management

ISO/IEC 27001:2022 — certified

Certification covers the information security management system: risk assessment and treatment, the applied controls, and the review cycle that keeps them current. The Statement of Applicability records which Annex A controls are in scope and, where one is excluded, the justification for excluding it.

CertificateStatement of ApplicabilityScope statementSurveillance status
Service organisation controls

SOC 2 Type II — certified

A Type II report covers operating effectiveness across a period rather than control design at a single point in time. The report sets out the observation window, the trust services criteria in scope, the tests performed and anything the assessor recorded.

Full reportObservation periodCriteria in scopeBridge letter

Under NDA

Additional documents.

Released under mutual NDA, which we send first. These are engineering and assessor documents rather than marketing material.

01
engineering

Architecture & Assurance Dossier

The full technical description: control plane and data plane component by component, every enforcement point, the egress matrix by edition, the control-plane authority model, identity and key custody, resilience and recovery, and supply chain.

02
engineering

Engineering Confirmation Register

Each target-architecture enforcement point, signed off by engineering, with the evidence that demonstrates it.

03
assessor

SOC 2 Type II report

Complete, including observation period, criteria in scope and assessor findings. A bridge letter is available for periods since the last report.

04
assessor

ISO/IEC 27001 certificate & Statement of Applicability

Scope, certification body, validity dates and the control-by-control applicability position.

05
engineering

Data-flow and egress matrix

What crosses each boundary, in which direction, under whose authority, for every edition.

06
completed

Security questionnaire responses

Completed against your framework, or against a standard questionnaire.

System access

Access to a working system.

Documentation describes the architecture; a running system demonstrates it. Access is arranged under NDA, at whichever depth is useful.

Level 01

Guided walkthrough

A live environment driven by our engineers, with your architects asking the questions. Typically the fastest way to establish whether the architecture matches the description.

Level 02

Hands-on environment

Credentialed access to an environment running against sample data, so your team can exercise the Studio, the graph, the gates and the audit trail directly rather than watching someone else do it.

Level 03

Scoped evaluation deployment

A data plane inside your own environment, connected read-only to sources you nominate. This is where the architectural claims become verifiable against your estate rather than ours.

What is verified at Level 03

The read-only posture at credential and network layer; egress observed at the boundary against the declared matrix; a consequential action refused without authority, and the refusal present in the audit trail; a decision replayed under the rule versions in force at the time; and the audit stream delivered into your own security-operations tooling.

Controls at a glance

The summary a first review usually needs.

AreaPosition
Data residencyRegion or enclave selected at deployment; the data plane runs inside the boundary you designate
Source accessRead-only, with your credentials, over the connection pattern your network allows
Raw data movementRecords remain in their system of record; the control plane holds metadata, policy and configuration only
EncryptionIn transit and at rest; bring-your-own-key and hardware-security-module backing available
Key custodyCustomer-held from the Professional edition upward
AuthenticationOAuth 2.0 with OIDC, SAML 2.0, mTLS; short-lived access tokens
AuthorisationRole- and attribute-based, enforced at graph traversal rather than applied to results
Execution isolationSandboxed runtime, read-only filesystem, allowlisted network, resource limits
AuditHash-chained and encrypted, auditor role only, no delete capability; streamed to your SIEM
Model trainingDataFab does not train models on customer data
Supply chainSigned releases, published software inventory, provenance attestation, customer approval before promotion
Deployment posturesCloud, private cloud, on-premises, air-gapped and sovereign

Deployment-specific values are set per environment and recorded in the Architecture & Assurance Dossier.

Next step

Documents and system access, under NDA.

The dossier, the certification reports and access to a working environment are released under a mutual NDA, which we send first.