Enterprise-grade security built for regulated industries

    Your data stays private, secure, and under your control. SOC 2 Type II certified, GDPR compliant, and deployable anywhere.

    SOC 2 Type II CertifiedGDPR Compliant

    Visit the Trust Center

    Access our security documentation, audit reports, and detailed information about how we protect your data.

    01 / Foundation

    Your data, encrypted and isolated.

    Every prompt, response, and document is protected by industry-leading encryption and strict tenant isolation. The principle is simple: your data stays yours.

    Your data never trains our models.

    Encryption in Transit & at Rest

    All data is encrypted using TLS 1.3 in transit and AES-256 at rest.

    Per-Tenant Isolation

    Complete data isolation between tenants with dedicated encryption keys.

    BYOK / KMS Support

    Bring your own keys or use our managed KMS for full control over encryption.

    Ephemeral Key-Pair Encryption

    Prompts and responses use ephemeral key pairs for additional security.

    Separate Encryption Layers

    Prompts, responses, and feedback are encrypted separately for defense in depth.

    Zero Trust Architecture

    Every request is authenticated and authorized, with no implicit trust.

    02 / Where it lives

    Deploy where your compliance demands.

    From multi-tenant SaaS to fully air-gapped on-premise, choose the model that matches your sovereignty and regulatory requirements.

    1

    Secure SaaS

    Hosted in secure EU and US regions with enterprise-grade infrastructure and 99.9% uptime SLA.

    • EU & US data centers
    • SOC 2 compliant infrastructure
    2

    Private Cloud / VPC

    Deploy within your own cloud infrastructure (AWS, Azure, GCP) for maximum control.

    • Customer-managed VPC
    • Network isolation
    3

    On-Prem / AI-in-a-Box

    Full air-gapped deployment for sovereign and highly regulated environments.

    • No external connections
    • Complete data sovereignty
    03 / Who can access it

    Identity, roles, and audit trails.

    Connect your identity provider, scope permissions to the right people, and keep a full record of who did what.

    SSO Integration

    Native support for Microsoft Entra, Okta, and Google Workspace.

    Role-Based Access Control

    Granular RBAC to control who can access what across your organization.

    Audit Logs

    Comprehensive audit trails for all user actions and system events.

    Team-Level Quotas

    Set usage limits and quotas at the team or department level.

    Sharing Controls

    Control how assistants and workflows are shared within your organization.

    API Key Management

    Secure API key creation, rotation, and revocation.

    04 / How the AI behaves

    Guardrails for responsible AI.

    Keep responses grounded in your knowledge base, filter unsafe content, and enforce the policies your organization has defined.

    Built-in Guardrails

    Configurable guardrails prevent misuse and enforce appropriate use policies.

    Context-Only Mode

    Restrict AI responses to only use information from your approved knowledge base.

    Bias & Harmful Content Filters

    Automated detection and filtering of biased, toxic, or harmful content.

    Customer-Defined Safety Policies

    Define your own safety policies and content guidelines for your organization.

    Security questions, answered.

    How Understand Tech protects your data across SaaS, private cloud, and air-gapped deployments.

    Key facts

    • Understand Tech is SOC 2 Type II certified and GDPR compliant.
    • Customer data is never used to train models, on any plan or deployment.
    • Data is encrypted with TLS 1.3 in transit and AES-256 at rest, with per-tenant isolation and dedicated encryption keys.
    • Customers can bring their own encryption keys (BYOK) or use the managed KMS.
    • SSO is supported with Microsoft Entra ID, Okta, and Google Workspace, alongside role-based access control and audit logs.
    • The platform deploys as SaaS in EU or US regions, inside the customer's own AWS, Azure, or GCP VPC, or fully air-gapped on-premise via AI-in-a-Box.
    • In air-gapped AI-in-a-Box deployments there are no external connections: documents, embeddings, and logs stay inside the customer perimeter.

    Chat with AI Assistant