DataFab / Trust Center
Security, compliance & assurance
The evidence, and how to obtain it.
DataFab is certified to ISO/IEC 27001:2022 and SOC 2 Type II. The architecture and governance model are described in full on this site. The certification reports, the technical dossier and access to a working system are available under NDA.
Certifications
Two certifications, both maintained.
Independently assessed, and kept current under continuing surveillance rather than achieved once. Certificates and reports are released under NDA.
ISO/IEC 27001:2022 — certified
Certification covers the information security management system: risk assessment and treatment, the applied controls, and the review cycle that keeps them current. The Statement of Applicability records which Annex A controls are in scope and, where one is excluded, the justification for excluding it.
SOC 2 Type II — certified
A Type II report covers operating effectiveness across a period rather than control design at a single point in time. The report sets out the observation window, the trust services criteria in scope, the tests performed and anything the assessor recorded.
Public documentation
What is already on this site.
Most of what a security architect asks for in a first review is published, not gated. These pages describe the architecture and the governance model in the detail a technical reader needs before deciding whether the rest is worth requesting.
Under NDA
Additional documents.
Released under mutual NDA, which we send first. These are engineering and assessor documents rather than marketing material.
Architecture & Assurance Dossier
The full technical description: control plane and data plane component by component, every enforcement point, the egress matrix by edition, the control-plane authority model, identity and key custody, resilience and recovery, and supply chain.
Engineering Confirmation Register
Each target-architecture enforcement point, signed off by engineering, with the evidence that demonstrates it.
SOC 2 Type II report
Complete, including observation period, criteria in scope and assessor findings. A bridge letter is available for periods since the last report.
ISO/IEC 27001 certificate & Statement of Applicability
Scope, certification body, validity dates and the control-by-control applicability position.
Data-flow and egress matrix
What crosses each boundary, in which direction, under whose authority, for every edition.
Security questionnaire responses
Completed against your framework, or against a standard questionnaire.
System access
Access to a working system.
Documentation describes the architecture; a running system demonstrates it. Access is arranged under NDA, at whichever depth is useful.
Guided walkthrough
A live environment driven by our engineers, with your architects asking the questions. Typically the fastest way to establish whether the architecture matches the description.
Hands-on environment
Credentialed access to an environment running against sample data, so your team can exercise the Studio, the graph, the gates and the audit trail directly rather than watching someone else do it.
Scoped evaluation deployment
A data plane inside your own environment, connected read-only to sources you nominate. This is where the architectural claims become verifiable against your estate rather than ours.
The read-only posture at credential and network layer; egress observed at the boundary against the declared matrix; a consequential action refused without authority, and the refusal present in the audit trail; a decision replayed under the rule versions in force at the time; and the audit stream delivered into your own security-operations tooling.
Controls at a glance
The summary a first review usually needs.
| Area | Position |
|---|---|
| Data residency | Region or enclave selected at deployment; the data plane runs inside the boundary you designate |
| Source access | Read-only, with your credentials, over the connection pattern your network allows |
| Raw data movement | Records remain in their system of record; the control plane holds metadata, policy and configuration only |
| Encryption | In transit and at rest; bring-your-own-key and hardware-security-module backing available |
| Key custody | Customer-held from the Professional edition upward |
| Authentication | OAuth 2.0 with OIDC, SAML 2.0, mTLS; short-lived access tokens |
| Authorisation | Role- and attribute-based, enforced at graph traversal rather than applied to results |
| Execution isolation | Sandboxed runtime, read-only filesystem, allowlisted network, resource limits |
| Audit | Hash-chained and encrypted, auditor role only, no delete capability; streamed to your SIEM |
| Model training | DataFab does not train models on customer data |
| Supply chain | Signed releases, published software inventory, provenance attestation, customer approval before promotion |
| Deployment postures | Cloud, private cloud, on-premises, air-gapped and sovereign |
Deployment-specific values are set per environment and recorded in the Architecture & Assurance Dossier.
Next step
Documents and system access, under NDA.
The dossier, the certification reports and access to a working environment are released under a mutual NDA, which we send first.