Book a Demo
Security
How RedLens AI protects your data and maintains platform integrity

Security is not just what we sell — it is how we operate. This page describes the technical and organizational measures RedLens AI uses to protect customer data and maintain platform integrity.

Infrastructure Security

Railway SOC 2 Type II
Anthropic SOC 2 Type II
AES-256 Encryption at Rest
TLS 1.3 in Transit
PostgreSQL Encrypted Database

RedLens AI is hosted on Railway, which maintains SOC 2 Type II certification. Our database is PostgreSQL hosted within Railway's secure infrastructure. All storage is encrypted at rest using AES-256. All data in transit is encrypted using TLS 1.3. No unencrypted connections are accepted.

AI Processing Security

All AI processing is performed via the Anthropic API, which maintains SOC 2 Type II certification. Customer assessment data submitted to the AI for analysis is processed under Anthropic's enterprise data handling policies, which prohibit use of API data for model training. We execute Data Processing Agreements with Anthropic covering customer data.

Access Controls

HIPAA Security Rule Compliance

BAA On Request
PHI Handling Policies
Breach Notification
Audit Controls

RedLens AI can act as a HIPAA Business Associate for qualifying healthcare customers. Business Associate Agreements (BAAs) are available on request — contact us to start that process. Our policies cover Administrative Safeguards (§164.308), Physical Safeguards (§164.310), and Technical Safeguards (§164.312).

Our platform includes specific modules designed to test AI systems against HIPAA Security Rule requirements and maps all findings to relevant HIPAA control sections for audit evidence.

Certifications Roadmap

Data Handling in Testing Modules

Vulnerability Disclosure

RedLens AI maintains a responsible disclosure policy. If you discover a security vulnerability in our platform, please report it to support@redlens.ai with the subject line "Security Disclosure." We commit to:

Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to remediate.

Incident Response

RedLens AI maintains an incident response plan covering detection, containment, eradication, and recovery. In the event of a security incident affecting customer data:

Air-Gapped Deployment

For federal law enforcement and healthcare organizations with strict network isolation requirements, RedLens AI offers a self-hosted deployment using on-premise open-weight models. In this configuration, no data leaves your network. Contact sales@redlens.ai for air-gapped deployment requirements.

Security Questions

For security questionnaires, penetration test reports, or to request our security documentation package: sales@redlens.ai