Security, privacy and
AI governance,
documented.
How we protect your data, what our AI is permitted to do, and where your data lives — backed by evidence, not adjectives.
Overview
OmniSense is an AI-native Security Operations platform for regulated, sovereign and critical-infrastructure environments. This page sets out our security, privacy and AI-governance posture in one place, so your security, procurement and data-protection teams can assess us without a questionnaire cycle. Where a capability is evidenced today, we say so; where it is in progress, we say that too.
| Requirement | Status | Detail |
|---|---|---|
| SOC 2 Type II | Evidenced | Security, Availability and Confidentiality. Unqualified opinion, no exceptions noted. Report available under NDA. |
| GDPR | Evidenced | Data Processing Agreement and Standard Contractual Clauses available; data-residency and retention controls. |
| Sovereign / in-country deployment | Evidenced | Regional deployment with in-boundary AI reasoning; air-gapped tier available. |
| ISO 27001 | In progress | Aligned to the standard; certification engagement to be scoped. |
| Independent penetration testing | Evidenced | Performed quarterly by an independent third-party firm; findings remediated to defined SLA. The report itself is not released; cadence, scope and remediation practice can be discussed under NDA. |
| FedRAMP / IL5 / CMMC | Not claimed | Not claimed. |
We do not market certifications we do not hold. Where we hold an attestation, we share the report itself under NDA — including the auditor’s test results, not just a logo.
The attestation
| Report | System and Organization Controls (SOC 2) Type II |
| Auditor | Accorp Partners CPA LLC (License PAC-FIRM-LIC-47383) |
| Examination period | 1 March 2025 – 15 August 2025 |
| Report issued | 12 October 2025 |
| Criteria | Security · Availability · Confidentiality |
| Opinion | Unqualified (clean): controls suitably designed and operating effectively throughout the period |
| Test results | “No exception noted” across the tested controls |
| Examined infrastructure | Amazon Web Services and Microsoft Azure, United States regions. AWS and Azure are carved-out subservice organisations. |
| Availability | Full report under NDA. A bridge letter covering the period since 16 August 2025 is available on request. |
The attestation covers the SIRP Labs control environment and the infrastructure described above. Deployments in other regions, including EU, KSA, Pakistan and air-gapped customer environments, operate under the same organisational control programme, but were not themselves inside the examined infrastructure boundary for that period. Extending audit scope to additional regions is planned for the next examination cycle. We would rather you read the report and find it matches what we told you.
AI trust
Most trust centers answer SOC 2. Few answer the question that matters when the software makes decisions: what is your AI permitted to do without asking us?
Where the reasoning runs
Sovereign and air-gapped deployments
All AI inference executes inside your boundary, on infrastructure you control. No external or third-party public LLM service is in the production reasoning path, and no security or customer data is transmitted to any model provider.
Cloud and hybrid deployments
Inference runs within your selected region. Where a third-party model provider is used, it is named in the sub-processor list with the data categories it receives.
We do not train foundation models on your data. The platform adapts to your environment using your analysts’ own decisions and outcomes, and that learning never leaves your tenant. Cross-tenant intelligence, where enabled, shares derived insights only, never raw data, under privacy-preserving controls, and is disabled entirely in air-gapped deployments.
AI governance controls
Autonomy is governed, and the limits are in code
Human oversight on consequential actions. The platform is a co-analyst, not an autopilot.
Authority is enforced in application logic, not in model prompts. The reasoning cannot exceed the authority you grant it, and cannot argue its way past a control.
Incident closure always requires a human decision. The system recommends; a person decides.
You set the line. Configurable authority levels, from mandatory approval through to higher autonomy for defined low-risk action classes, with human override at all times.
Every decision is reproducible
Evidence-grounded verdicts. Each verdict identifies the specific evidence and sources relied upon, and what was set aside, with a confidence score.
Full decision trail from alert to action, retained and reviewable for internal audit and regulatory review.
Release discipline. Changes are validated against a frozen regression set before release, so behaviour does not drift silently between versions.
The architecture is aligned to the principles emphasised for AI used in consequential settings (human oversight, traceability, logging, technical documentation and risk management), including the EU AI Act (obligations for general-purpose AI models with systemic risk enforceable 2 August 2026), NIS2 and DORA evidentiary needs, and sovereign frameworks such as the KSA NCA and Türkiye BDDK/KVKK regimes. We can support your own assessment with system documentation and decision-trail evidence.
Data residency and deployment
You choose where your data lives and where the reasoning happens.
| Deployment model | Data residency | AI inference | External LLM |
|---|---|---|---|
| Cloud | Selected sovereign region | In-region | Named in sub-processors if used |
| Hybrid | Customer environment + region | In-region | Named in sub-processors if used |
| Sovereign / on-premises | Customer data centre | Inside customer boundary | None |
| Air-gapped | Customer data centre, isolated | Customer-hosted, isolated | None. Nothing leaves the boundary |
- Regional deployments are available in the European Union (Microsoft Azure), Kingdom of Saudi Arabia (Oracle Cloud Infrastructure, Riyadh), United States (Amazon Web Services / Microsoft Azure / DigitalOcean) and Pakistan (Khazana). Air-gapped deployments run entirely on customer-owned infrastructure.
- Tenant isolation is structural. It is enforced at the data-access layer rather than by application-level filtering.
- Encryption in transit (TLS 1.2+) and at rest; credentials and secrets stored encrypted and segregated from application data.
- Per-request compliance controls govern logging verbosity, PII redaction level and data residency.
- Retention and deletion are configurable; data is returned or deleted on termination in accordance with the agreement.
Controls
Grouped as assessed under the Trust Services Criteria. Full control-by-control detail is available under NDA.
Infrastructure security
- Production environment access restricted and reviewed
- Unique authentication enforced for production databases
- Encryption key access restricted to authorised personnel
- Network segmentation with deny-by-default firewalls
- Multi-factor authentication enforced for engineering access
- Infrastructure time synchronisation (NTP)
Organisational security
- Employee background checks performed
- Security awareness training on hire and annually
- Policy acknowledgement on hire and annually
- Code of business conduct maintained and communicated
- Asset inventory maintained
- Documented disciplinary process for security violations
Product security
- Role-based access control on least privilege
- Tenant isolation enforced at the data-access layer
- Encryption in transit and at rest
- Secure development lifecycle with mandatory peer review
- Branch protection on protected repositories
- Dependency and secret scanning in the pipeline
- Quarterly external penetration testing by an independent third party
Internal security procedures
- Change management, authorised before production
- Documented incident response and escalation
- Vendor and sub-processor risk assessment
- Annual risk assessment and management review
- Business continuity and disaster recovery plans established
- Scheduled, encrypted backups with integrity verification
- Capacity and availability monitoring with alerting
- Logging, audit trail and periodic access reviews
- Vulnerability management with defined remediation service levels
Data and privacy
- Data classification policy established
- Data retention procedures established
- Customer data returned or deleted on termination
- Per-request PII redaction and residency controls
A documented information-security policy set is maintained, covering information security, access control, risk management, change management, incident management, encryption, data classification, retention, backup, business continuity, disaster recovery, vendor management, physical security, media disposal, endpoint security, password, acceptable use, vulnerability management and code of business conduct — with acknowledgement on hire and annually, managed through a continuous control-monitoring platform.
Sub-processors and data handling
Infrastructure sub-processors
| Sub-processor | Role | Region | Data |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure | United States | Platform and customer security data (US deployments) |
| Microsoft Azure | Cloud infrastructure | US / EU | Platform and customer security data (US and EU deployments) |
| Oracle Cloud Infrastructure | Cloud infrastructure | Saudi Arabia (Riyadh) | Platform and customer security data (KSA sovereign deployments) |
| Khazana | Cloud infrastructure | Pakistan | Platform and customer security data (Pakistan deployments) |
| DigitalOcean | Cloud infrastructure | United States | Platform workloads (US deployments) |
Corporate sub-processors
| Sub-processor | Role | Region | Data |
|---|---|---|---|
| Sprinto | Continuous compliance monitoring | United States | Employee and policy-acknowledgement records; control evidence |
| Google Workspace | Email and collaboration | United States | SIRP Labs employee data; business correspondence |
| GitHub | Source code management and build | United States | Source code and build metadata; no customer security data |
For sovereign and air-gapped deployments, no third-party model provider receives customer data, and therefore none appears as a sub-processor for AI inference. Where a model provider is used in a cloud deployment, it is named explicitly with the data categories it receives.
Data we process
| Category | Detail |
|---|---|
| Customer security telemetry | Alerts, logs and events from the customer environment, which may contain personal data such as usernames, IP addresses and device identifiers. |
| Customer account data | Names, business email addresses and role information for platform users. |
| Employee data | Personal data of SIRP Labs personnel, processed for employment and access-control purposes. |
Frequently asked
Disclosure and contact
Vulnerability disclosure
We welcome reports from security researchers and customers. We acknowledge reports on receipt, keep reporters updated through remediation, and do not pursue researchers acting in good faith. Vulnerabilities identified through our quarterly independent testing programme are remediated to defined service levels.
| Purpose | Contact |
|---|---|
| Security and trust enquiries | [email protected] |
| Vulnerability disclosure | [email protected] |
| Data protection / privacy | [email protected] |
| Commercial | [email protected] |
This page summarises SIRP Labs Inc.’s control posture at the date of issue. It is a summary and not a substitute for the SOC 2 Type II report, which is available under NDA. Posture is reviewed continuously and customers under contract are notified of material changes.
Questions we haven't answered here?
Full SOC 2 report, DPA, sub-processor detail and pen-test cadence — available under NDA.