Skip to main content
NEWThe top 25 industrial manufacturing use cases of 2026.Get the 2026 edition
SecuritySOC 2 · HIPAA · CMMC · GDPR

Built for scale, ready for enterprise

Your data security and privacy are fundamental to how we've built our platform.

Our trust center
Secure
Enterprise-grade protection at every layer.
Transparent
Inspect every operation on your data.
Private
Your data stays yours, always.
INDEPENDENTLY AUDITED

SOC 2 & HIPAA compliant

Our certifications reflect our commitment to maintaining the highest standards for security, availability, and confidentiality.

Reports, policies and live control status
  • SOC 2SOC 2 Type II, audited annually

    Independently audited controls covering security, availability, and confidentiality. Report available under NDA.

  • HIPAAHIPAA, BAA available

    Protected health information is handled under a signed BAA, with access logged down to the record.

  • CMMCCMMC Level 2

    Aligned to the practices defense suppliers are held to, so CUI stays inside the boundary you control.

  • GDPREU data protection

    Data residency, deletion, and subject-access requests handled as a matter of course, not a special case.

HOW IT IS ENFORCED

Follow one request.

A person asks an application for something. Four gates decide what happens, and each one leaves a record.

  1. 01

    Identity

    The request arrives with a person attached, through your identity provider rather than a shared service account.

    Who asked
  2. 02

    Entitlement

    What they may see is resolved for this request, against the roles you set. A permission change takes effect on the next request, not the next login.

    What they may see
  3. 03

    Execution

    The application answers from the governed copy of your data, inside your boundary. Your data is never used to train a model.

    What it read
  4. 04

    Audit

    The action, the inputs and the result are written to an audit log you can export. Every change to the application itself was reviewed and logged before it shipped.

    What happened
CONTROLS

The controls come with the system

We plug into shops that answer to primes, regulators, and customers.

  • Encrypted end to end

    AES-256 at rest, TLS 1.2+ in transit. Always on.

  • Never trained on

    Your data is never used to train models - yours or ours.

  • SSO & SAML

    Okta, Entra, Google. Provision and revoke in one place.

  • Role-based access

    Least-privilege roles down to the data-source level.

  • Full audit logs

    Every query, connection, and export is logged.

  • Isolated by tenant

    Your context layer lives in its own isolated store.

DEPLOYMENT

It runs where your data is allowed to be.

Four models, from a shared instance to an air-gapped one. The platform is Kubernetes-based, so it is portable across clouds and an independent instance stands up per customer.

ModelWhat it isIsolation
Multi-tenant cloudA shared instance we run, with separation at the user level. The lowest cost way in.User level
Single tenantRecommendedA dedicated instance in our cloud or in yours, isolated at the application or the network level. You may bring your own approved model.Application or network
GovCloudFull deployment on GovCloud, for work that cannot sit in a commercial region.Government region
On premiseFor operations with no hyperscaler, or an air-gapped one. Kubernetes-native where the cluster exists, otherwise a single isolated image with no inbound or outbound route.Your perimeter

Whichever model you pick, the applications ship as client-owned code with every change reviewed and logged, the model instance runs under no-training terms, and your data is never used to train a model.

How your data is handled

Data handling01 - 03
01

Isolated sandbox execution

Every data extraction and transformation runs in a completely isolated environment that's destroyed after each job. Your data never touches shared infrastructure, is never stored beyond the active session, and automatically wipes within 6 hours - ensuring zero data persistence or leakage between runs.

Zero data persistence
Extraction environments are ephemeral and fully destroyed after each job completes, leaving no trace of your data.
Complete isolation
Each workflow runs in its own containerized sandbox with no shared resources, preventing any cross-contamination between jobs or customers.
Automatic cleanup
All temporary data, logs, and processing artifacts are permanently deleted within 6 hours.
02

No training on your data - ever

Your data powers your workflows - nothing else.

Zero model training
We never use your data to train, fine-tune, or improve our AI models under any circumstances.
Contractual guarantees
Our foundation model providers are contractually prohibited from accessing or learning from customer data.
Complete data isolation
What you process in Structify is used exclusively for your operations and never leaves your control.
03

Granular access controls

Control exactly who sees what, at every level.

Team-based permissions
Set role-based access policies across your entire organization to ensure proper data governance.
Connector restrictions
Limit which users can access specific data sources, preventing unauthorized connections to sensitive systems.
Workflow-level security
Define granular permissions for individual datasets and workflows so users only access what they need.
Trust center

See the controls behind the badges

Our rigorous controls and operational practices are regularly validated to ensure continued compliance.