Security

Security is foundational to SafeForLLM. Our service exists to protect sensitive data, so we hold ourselves to the highest standards when it comes to safeguarding your information.

Encryption everywhere

All data is encrypted in transit with TLS 1.2+ and at rest using AES-256. API keys and secrets are stored in secure vaults, never in source code.

Secure infrastructure

Our services run on hardened, regularly patched infrastructure within AWS. Access is restricted by network-level controls, firewalls, and least-privilege IAM policies.

Access controls

All internal access to production systems requires multi-factor authentication. Administrative actions are logged and auditable. Employee access follows the principle of least privilege.

Application security

We employ input validation, parameterised queries, CSRF protection, rate limiting, and regular dependency audits. Our codebase is continuously scanned for vulnerabilities.

Incident response

We maintain a documented incident response plan. In the event of a security incident, affected users will be notified promptly in accordance with applicable regulations.

Data isolation

Each user's data is logically isolated. Redaction mappings and outputs are scoped to your account and cannot be accessed by other users. Uploaded documents are stored in private, per-request storage paths with signed, time-limited access URLs.

Third-party services

We carefully vet all third-party providers. Our primary infrastructure partner is AWS, and payment processing is handled by Stripe — both of which maintain SOC 2 and PCI DSS compliance. We do not share your content with any third party for purposes outside of delivering the Service.

Responsible disclosure

If you discover a security vulnerability, we encourage responsible disclosure. Please contact us at support@safeforllm.com with details. We commit to acknowledging reports within 48 hours and working with you to resolve issues promptly. We will not take legal action against researchers who follow responsible disclosure practices.

Questions?

For security-related enquiries, reach out to support@safeforllm.com.