Security and compliance

Security, data handling, and compliance

This page exists so a security review is a link rather than a two week email thread. It states what we collect, where it goes, who can reach it, and what we do and do not do with it. If something you need is missing, ask and we will add it here rather than answer it once in private.

AICPA SOC 2
SOC 2 Type II Full report, control listing, and the most recent penetration test summary are available under NDA. Request them at security@infis.ai.

Data handling

What is collected
Supplier master records, material and BOM data, purchase orders and spend history, quality records, and the requisitions you route to Infis. Plus account data for your users: name, work email, role, and authentication events.
What is not collected
We do not ingest HR data, patient or clinical data, or personal data about your employees beyond the account fields above. Connectors are scoped to named objects rather than granted broad read.
Where it is stored
Google Cloud Platform. Primary region is us-central1. EU and other regional residency is configurable at contract time and is set per tenant before the first connector runs.
Retention
Customer data is retained for the life of the contract. On termination, production data is deleted within 30 days and backups age out within 35 days. Deletion is confirmed in writing on request.
Encryption
TLS 1.2 or higher in transit. AES-256 at rest. Keys are managed through the cloud provider KMS with rotation.
Backups
Encrypted daily, retained 35 days, restore tested on a recurring basis.

Access controls and authentication

  • SAML 2.0 and OIDC single sign on, with SCIM directory provisioning and deprovisioning.
  • Role based access, scoped by category and site, so a buyer sees the categories they own.
  • Enforced MFA for any account not behind your SSO, including ours.
  • Least privilege internally. Production access requires named approval, is time bound, and is logged.
  • Every connector runs on a service account you issue, scoped to named objects, revocable by you at any time without involving us.

AI specific handling

This is the section most reviewers actually want, and the one most vendors leave vague.

Used for inference
Your supplier, material, spend, and quality data is used to run scoring, sourcing, and classification inside your tenant only.
Not used for training
Customer data is never used to train, fine tune, or evaluate shared models. There is no cross tenant learning. Your data does not improve another customer's instance.
Model providers
Inference runs against enterprise API tiers with zero data retention terms in place. Prompts and completions are not retained by the provider and are not used for provider model training.
Prompt and output retention
Agent inputs and outputs are retained inside your tenant as part of the audit trail, because a record you cannot inspect is not an audit trail. Retention follows your contract term and is deleted with the rest of your data.
Human review
No Infis employee reads your data as part of normal operation. Support access requires a named request from you, is time bound, and appears in your audit log.

Subprocessors

Current as of this page. Customers on an active contract are notified before a subprocessor is added.

SubprocessorPurposeRegion
Google Cloud PlatformInfrastructure and data storageUnited States, or your contracted region
AnthropicModel inference, zero retention enterprise termsUnited States
OpenAIModel inference, zero retention enterprise termsUnited States
Auth0Authentication and SSOUnited States
SentryApplication error monitoring, scrubbed of customer dataUnited States

Platform posture

  • Connectors are read only by default. Infis does not write to your ERP or quality system.
  • Tenant isolation at the data layer. No shared tables across customers.
  • Every agent action that leaves Infis sits behind a named human approval unless you explicitly open that gate.
  • Every score, alert, classification, and agent action retains its source records and timestamp, and the log is exportable.
  • Vulnerability scanning on dependencies and images in CI. Third party penetration test performed annually.

Security contact

Security questionnaires, the SOC 2 Type II report, penetration test summaries, and DPA requests: security@infis.ai. We answer standard questionnaires including CAIQ and SIG Lite.

To report a suspected vulnerability, email security@infis.ai with steps to reproduce. We acknowledge within two business days and will keep you updated until it is closed.