How Colendi AI keeps regulated work secure: certifications, data and model governance, deployment options from SaaS to air-gapped, and the providers we rely on. Reports and detailed documentation are available on request.
Independently audited, and compliant with the regulations our customers answer to. Reports are available under NDA on request.
SOC 2Independently audited controls for security, availability and confidentiality.
ISO 27001Certified information security management system across the platform.Data stays where regulation says it must stay — and no model output becomes an action without passing governance.
Customer data is stored in Türkiye by default, with residency options that respect local regulation in every deployment.
Encryption in transit and at rest, PII redaction before inference, and zero retention with model providers.
Role-based access controls, with every access to personal data and every action on a case logged and auditable.
Complete-case grading, regression tests on every release, and a published pass rate for every production module.
High-stakes actions require human decision — with a named owner, an escalation path and a clock.
Inputs, checks, decider and outcome are recorded immutably; every decision can be reconstructed after the fact.
The same governed platform, from managed SaaS to fully air-gapped — chosen with your risk team, not imposed on it.
| Option | Infrastructure | Data boundary | Updates |
|---|---|---|---|
| Multi-tenant | Managed cloud with secure logical isolation | In-region residency, tenant-level separation | Continuous, fully monitored |
| Single tenant | Dedicated, fully isolated infrastructure | Dedicated data plane, custom configuration | Automatic, on your schedule |
| Your cloud | Runs inside your own cloud account | Data never leaves your organization | You control governance and timing |
| On-premise | Fully air-gapped, zero external dependencies | Everything stays on site | Maintained on site with your team |
Scope varies by deployment option — on-premise deployments have zero external dependencies. Full, current list available on request.
| Provider | Purpose | Notes |
|---|---|---|
| AWS | Cloud infrastructure | Region selected per deployment |
| Google Cloud | Cloud infrastructure | Region selected per deployment |
| Microsoft Azure | Cloud infrastructure | Region selected per deployment |
| Meta Platforms | WhatsApp Business messaging channel | Where messaging channels are in scope |
| Model providers | Commercial and open-source LLM inference | Zero retention; PII redacted before inference |
Oversight, guardrails, explainability, data protection, fairness and continuous evaluation shape how every Mind product is designed, deployed and governed. Read them in full on our AI Safety page.
Security reviews, due-diligence questionnaires and reports: info@colendiai.com