// compliance

Security you can verify.

SOC 2, GDPR, CCPA, and ISO 27001 posture below. Where we are attested, we say so. Where we are aligned but not certified, we say that too. Where the attestation is planned, we name the gap.

last reviewed
next review

Certifications and Standards

SOC 2 Type II

Erebine operates inside colocation facilities that hold their own SOC 2 Type II attestations covering the security, availability, and confidentiality Trust Services Criteria for the physical environment. Erebine's own SOC 2 attestation is in progress; the report is not yet issued.

Scope: physical environment (attested by the colo provider). Application-layer SOC 2 attestation in progress; expected report fiscal-year 2026.

Planned

GDPR

Aligned with the General Data Protection Regulation. The platform implements data-subject controls including right-to-erasure, data export for portability, and anonymization. Contact contact@erebine.ai to request a Data Processing Agreement.

Aligned

CCPA

Consumer rights for California residents are honored through the same data-subject controls used to satisfy GDPR (access, deletion, and portability). "Do Not Sell or Share" is a self-service setting under Dashboard → Settings → Privacy: we do not sell or rent personal information in the first place, and turning the setting on records the explicit opt-out and excludes the account from marketing campaign targeting. Global Privacy Control signals from the browser are honored as the same request. Anything the in-product controls do not cover can be sent to contact@erebine.ai and is honored within thirty days.

Aligned

ISO 27001

Our information security management system is designed to align with the ISO 27001 control families. Formal ISO 27001 certification is planned and not yet issued.

Planned

Security Practices

  • Encryption in transit: TLS 1.2 minimum on every public endpoint; TLS 1.3 preferred. Internal router-to-agent communication uses CURVE-encrypted ZeroMQ transport with mutual authentication via Curve25519 keys for every router-agent connection.
  • Encryption at rest: AES-256-GCM authenticated encryption on persistent storage. Key rotation is operator-controlled per deployment.
  • Access control: Three role tiers (operator, admin, project member) plus per-endpoint API-key scopes. Least-privilege defaults; no implicit cross-project visibility.
  • Monitoring and incident response: Operational monitoring and incident response procedures are maintained by the operator of each deployment.
  • Vulnerability management: Dependency and platform CVEs are tracked against the build graph and patched on the next router release after disclosure.

Trust and Safety

  • Child safety: We prohibit CSAM and report apparent CSAM to NCMEC on actual knowledge, with evidence preservation. An optional automated scanning surface can be activated per deployment. The minimum age is 18.
  • Non-consensual intimate imagery: We operate a notice-and-removal process; report to contact@erebine.ai.
  • Content reporting: Users can report content in-product or at contact@erebine.ai; an admin review queue triages reports.

Copyright

We respond to DMCA notices and terminate repeat infringers. See /dmca for our designated agent and the notice and counter-notice process.

Sanctions and Export

Use of the service is subject to US sanctions and export-control law. Denied-party and sanctioned-destination screening of accounts, payments, and model uploads can be activated per deployment; the control floor ships in every release. Registration country is collected at signup to support that screening.

Data Residency

Erebine allows you to choose where your data is stored by giving you full access to Erebine Inference Microservice (EIM) nodes. Shared services are operated in the United States.

Enterprise customers can request EIM infrastructure with custom data residency requirements.

Data Processing Agreement

We provide a Data Processing Agreement (DPA) for customers who need to comply with GDPR and other data protection regulations. Contact contact@erebine.ai to request a DPA; we respond within five business days.

Reporting Security Issues

If you discover a security vulnerability, report it to contact@erebine.ai. We acknowledge responsible disclosure within one business day and aim to triage within five. A coordinated-disclosure window is negotiated per report.

Automated scanners and security researchers can fetch the machine-readable disclosure metadata at /.well-known/security.txt (RFC 9116).