Trust Center

Last Updated: August 20, 2026

Everything a security or procurement reviewer needs, in one place. We publish what we actually do — including what we do not do — and every claim on this page points at the control behind it.

Our compliance posture, stated plainly

Demeterics has not engaged a third-party auditor. We maintain the control set a SOC 2 Type II audit examines — written policies, incident response, change management, vendor assessment, data classification — and we assess ourselves against it and publish the result, including the gaps. Our most recent internal assessment (March 2026) scored 52/100 against SOC 2 common criteria. We will engage an auditor when customer demand justifies the cost.

We would rather tell you that than let you discover it during a security review.

Zero-Day Retention

Retention is configured per API key, so a single account can run zero-retention keys for sensitive workloads alongside longer-retention keys for debugging:

  • 0 days (ZDR): content never stored
  • 30 days: content deleted by an automated daily job
  • 90 days (default): content deleted by an automated daily job
  • 365 days: content deleted after one year
  • On demand: DELETE /api/v1/data deletes your content immediately

What we have

ControlStatusDetail
Zero-Day RetentionShippedEnforced at ingestion; per-API-key
Configurable retention + automated deletionShippedDaily cron; 0/30/90/365 days per key
GDPR deletion & exportShippedDELETE /api/v1/data, export to CSV/JSON
Encryption in transit & at restShippedTLS 1.3; AES-256 at rest
Provider key encryptionShippedCloud KMS, 15-minute in-memory cache, every decrypt audit-logged
Bring-your-own-key, never persistedShippedTransient dual-key mode — your provider key is used and discarded
API key hashingShippedbcrypt, cost factor 12
Tenant isolationShippeduser_id filtering on every query
Written security policiesShippedIncident response, risk register, change management, data classification, vendor management, secret rotation, security training, hardening roadmap
Incident response planShippedP1–P4 severity matrix, named incident commander, 72-hour breach notification
Automated security scanning in CIShippedSecret detection and public-claims accuracy block the build; dependency, static and container scanning run on every change as advisory checks
Internal security auditShippedMost recent August 2026: nine findings identified, fixed, deployed and re-verified in production
Coordinated vulnerability disclosureShippedsecurity.txt, 2-business-day acknowledgement
Subprocessor transparencyShippedFull list published, 30-day change notice

What we do not have

A trust page that lists only strengths is not a trust page. These are the gaps a reviewer would find anyway, so we list them ourselves, with where they stand.

ItemStatusPosition
SOC 2 Type II certificationNot certifiedNo auditor engaged. Our internal control set and self-assessment are available in the security package.
ISO 27001 / ISO 42001Not certifiedNot pursued at this stage.
Third-party penetration testPlannedNot yet performed. Internal adversarial audits are performed and documented.
HIPAA BAANot offeredWe do not sign BAAs and Demeterics should not be used for PHI.
EU / APAC data residencyNot offeredAll data is processed in us-central1 (United States).
Enterprise SSO (SAML/SCIM)PlannedAuthentication is Google OAuth2 today.
Organisation / team accountsPlannedAccounts are currently per-user.
Contractual SLANot offeredThe service runs on a best-effort basis. See Terms §9.
Public status pagePlannedService notices are emailed to affected accounts.
Paid bug bountyNot offeredWe run a coordinated disclosure program instead.

Published documents

Request our security package

For a vendor security review we provide, on request: a security whitepaper with control-level evidence, a completed CAIQ-Lite questionnaire, a Data Processing Agreement template with Standard Contractual Clauses, our incident response summary, and a dated compliance roadmap.

We respond within 2 business days. We use your details only to send the package and to follow up.

Security contact

Vulnerability reports: security@demeterics.com (see security.txt).
Everything else: support@demeterics.com.