Security, Compliance, and Trust at Intelligent Automation
We protect the businesses we manage with the same security program we'd want for our own. Below is a transparent view of our compliance posture, security controls, and active certifications — not a marketing pitch.
Our Active Compliance Programs
Real-time view of where we stand across our committed frameworks. Numbers update from the same control evidence we use internally.
How We Secure Your Data
The control families that protect every byte we manage on your behalf.
Identity & Access
Zitadel SSO with Argos Verify push MFA on every staff login. Least-privilege roles, scoped service accounts, no shared credentials.
Endpoint Defense
Sophos MDR XDR on every managed endpoint. Argos Patch drives continuous remediation with security-only rings and audit-first dispatch.
Network
Cloudflare-fronted public ingress. Admin access is Tailscale-only — no public SSH, no exposed control planes.
Data Protection
Encrypted at rest (DigitalOcean volumes + DO Spaces SSE) and in transit (TLS 1.2+). Secrets segregated per-tenant.
Continuous Monitoring
CrowdSec behavioural IDS, cAdvisor and Uptime-Kuma. Per-container telemetry retained at 1-minute resolution for incident forensics.
Incident Response
DFIR-IRIS-style runbooks with blast-radius mapping across the dependency graph. 24-hour SLA on critical incidents.
Sub-processors
Third-party services that may process customer data on our behalf. We review each annually.
| Provider | Service | Data Region | Last Reviewed | Trust Page |
|---|---|---|---|---|
| DigitalOcean | Cloud infrastructure (VPS, Spaces) | NYC3 | Not reviewed | digitalocean.com/trust ↗ |
| Cloudflare | DNS, WAF, DDoS, CDN | Global | Not reviewed | cloudflare.com/trust-hub ↗ |
| Microsoft Azure | Identity, code signing | East US | Not reviewed | servicetrust.microsoft.com ↗ |
| SSL.com | Document signing CA | USA | Not reviewed | ssl.com/info/legal ↗ |
| Anthropic | LLM reasoning for Argos AI features (no training on customer data) | United States | Not reviewed | www.anthropic.com/legal/commercial-terms ↗ |
| ElevenLabs | Text-to-speech / consented voice synthesis for marketing audio | United States | Not reviewed | elevenlabs.io/dpa ↗ |
| Sophos | MDR, endpoint defense | USA | Not reviewed | sophos.com/legal/trust-center ↗ |
| SMTP2GO | Transactional email | USA | Not reviewed | smtp2go.com/legal ↗ |
Documents & Reports
Security and compliance documentation. Public items download directly; gated items require a quick access request.
How We Use AI — EU AI Act Art 50 Disclosure
IA's plain-language public disclosure of how and where it uses AI.
Download ↓Need our SOC 2 readiness package or full controls evidence?
Sign a mutual NDA in 2 minutes and we'll deliver the complete report — controls matrix, sub-processor list, recent assessment outputs, and remediation status.
Request the Full Trust Report