Security
How RedLens AI protects your data and maintains platform integrity
Security is not just what we sell — it is how we operate. This page describes the technical and organizational measures RedLens AI uses to protect customer data and maintain platform integrity.
Infrastructure Security
✓ Railway SOC 2 Type II
✓ Anthropic SOC 2 Type II
✓ AES-256 Encryption at Rest
✓ TLS 1.3 in Transit
✓ PostgreSQL Encrypted Database
RedLens AI is hosted on Railway, which maintains SOC 2 Type II certification. Our database is PostgreSQL hosted within Railway's secure infrastructure. All storage is encrypted at rest using AES-256. All data in transit is encrypted using TLS 1.3. No unencrypted connections are accepted.
AI Processing Security
All AI processing is performed via the Anthropic API, which maintains SOC 2 Type II certification. Customer assessment data submitted to the AI for analysis is processed under Anthropic's enterprise data handling policies, which prohibit use of API data for model training. We execute Data Processing Agreements with Anthropic covering customer data.
Access Controls
- Per-role permission enforcement is active for all accounts (admin / analyst / read-only): read-only accounts cannot make changes, and destructive, billing, or integration-configuration actions require an administrator role
- Individually credentialed staff accounts — salted password hashing, server-side session expiry, and TOTP-based multi-factor authentication (authenticator app plus single-use backup codes) available on every account
- Principle of least privilege — internal accounts are provisioned only to staff who need them
- Customer data is logically isolated — no customer can access another customer's data
- All access to production systems is logged and audited
- API keys are rotated regularly and stored in encrypted environment variables
HIPAA Security Rule Compliance
✓ BAA On Request
✓ PHI Handling Policies
✓ Breach Notification
✓ Audit Controls
RedLens AI can act as a HIPAA Business Associate for qualifying healthcare customers. Business Associate Agreements (BAAs) are available on request — contact us to start that process. Our policies cover Administrative Safeguards (§164.308), Physical Safeguards (§164.310), and Technical Safeguards (§164.312).
Our platform includes specific modules designed to test AI systems against HIPAA Security Rule requirements and maps all findings to relevant HIPAA control sections for audit evidence.
Certifications Roadmap
- SOC 2 Type II — Audit begins Q1 2027, certification targeted Q3 2027
- HIPAA BAA — Available on request for qualifying healthcare customers
- FedRAMP — Groundwork begins Q3 2027 for federal law enforcement
- NIST AI RMF alignment — Fully mapped in current platform
Data Handling in Testing Modules
- PHI Egress Scan — pasted data samples are scanned in-memory and never stored; scan history keeps only redacted matches and source labels, so a stored scan cannot be re-run against its original input
- Evidence Packages — generated as immutable point-in-time snapshots; packages are never edited after generation, and every control is labeled evidence-recorded, partial, or gap — we document evidence, we do not certify compliance
- Vendor AI Assessment (TPRM) — no attack traffic is sent to a third-party target without a recorded vendor-side authorization; the documented-authorization path additionally requires review by RedLens staff before any active scanning
- Prompt & Guardrail Hardener — free static analyses run without billed model calls and are not persisted; only full assessments are saved to your tenant's history
Vulnerability Disclosure
RedLens AI maintains a responsible disclosure policy. If you discover a security vulnerability in our platform, please report it to support@redlens.ai with the subject line "Security Disclosure." We commit to:
- Acknowledge receipt within 48 hours
- Provide a status update within 7 days
- Resolve critical vulnerabilities within 30 days
- Credit researchers who responsibly disclose vulnerabilities
Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to remediate.
Incident Response
RedLens AI maintains an incident response plan covering detection, containment, eradication, and recovery. In the event of a security incident affecting customer data:
- Affected customers will be notified within 72 hours of confirmed breach
- Notification will include nature of incident, data affected, and remediation steps
- Post-incident reports will be provided upon request
- HIPAA breach notification procedures apply to healthcare customers
Air-Gapped Deployment
For federal law enforcement and healthcare organizations with strict network isolation requirements, RedLens AI offers a self-hosted deployment using on-premise open-weight models. In this configuration, no data leaves your network. Contact sales@redlens.ai for air-gapped deployment requirements.
Security Questions
For security questionnaires, penetration test reports, or to request our security documentation package: sales@redlens.ai