Third Party Index

Snapshot 18890

Document
Trust center
URL
https://trust.wolfia.com/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
1065054 bytes
SHA-256 (raw)
638f2e0de76a7e9c0fa48138d668cc3de07e05bbc390d348b9cdec70d2778fbf
SHA-256 (normalized text)
a9387e68dc4212fe306366cd01fc341d3392267a187b854334ced185119d43d3

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Wolfia Trust Center
We help sales, security, and support teams get answers in seconds without depending on subject-matter experts. Our AI agent connects to every source that already holds the truth (Google Drive, Notion, Slack, email, website, trust center, SOC 2 docs, etc.). It keeps that knowledge graph fresh on its own and drafts, validates, and formats responses to customer questions, security questionnaires, and RFPs, all in the background, so your team just reviews and ships.
Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.
Skip to main content
Wolfia Trust Center
We help sales, security, and support teams get answers in seconds without depending on subject-matter experts.
Our AI agent connects to every source that already holds the truth (Google Drive, Notion, Slack, email, website, trust center, SOC 2 docs, etc.). It keeps that knowledge graph fresh on its own and drafts, validates, and formats responses to customer questions, security questionnaires, and RFPs, all in the background, so your team just reviews and ships.
[email protected]
⌘K
OverviewDocumentationControlsSubprocessors
Loading content...
Certifications
Trusted by
Amplitude
Juicebox
Miro
Peregrine
Handshake
Medallia
ThoughtSpot
Eightfold
Sardine
CircleCI
Onyx
Contact supportReport a vulnerability
Trust center by Wolfia: AI trust center & security questionnaire automation
Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers
Documentation
Featured
Web Application and API Penetration Test Report
Certificate of Liability Insurance
Wolfia Architecture Diagram
Wolfia Platform Security Overview
SOC 2 Type 2 Report
Subprocessors
Amazon Web Services · United States
Primary cloud-hosting and infrastructure platform and AI services
United States
Anthropic · United States
LLM inference via Claude API
United States
Google · United States
LLM inference (Gemini) via Vertex AI on Google Cloud, used only as a fallback
United States
Microsoft Azure · United States
API-based AI inference only (Azure OpenAI Service, Azure AI Foundry, Azure AI Document Intelligence). No customer data is hosted or stored on Azure infrastructure.
United States
OpenAI · United States
LLM inference via OpenAI API
United States
Controls
Access control
Robust identity and permission safeguards prevent unauthorized system access and enforce least-privilege principles
Single sign-on support
Automated user provisioning
Role-based access control
Formal onboarding and off-boarding
Encrypted administrative access
Annual access reviews
Multi-factor authentication
Data security
Encryption, retention and classification controls protect customer information throughout its lifecycle
Encryption at rest
Encryption in transit
Data retention and deletion policy
Full-disk workstation encryption
Data classification scheme
Application security
A mature secure development lifecycle and continuous testing keep the platform resilient against software threats
Secure development policy
Static code analysis
Dependency and image vulnerability scanning
Annual third-party penetration testing
Web application firewall
Secret scanning and rotation
Trusted container images
Deployment approval workflow
Frequently asked security questions
Is Wolfia secure?
Wolfia operates this public trust center. It publishes 5 independent compliance certifications, security documentation available on request, and a published list of its subprocessors.
Is Wolfia SOC 2 compliant?
Yes. Wolfia maintains SOC 2 Type II compliance. You can review this in the compliance section of this trust center.
Who are Wolfia's subprocessors?
Wolfia discloses its subprocessors in this trust center, including Amazon, Anthropic, and googlecloudplatform.com. See the subprocessors section for the complete list.
How do I request Wolfia's security documentation?
You can request access to Wolfia's security documentation directly through this trust center. Submit an access request and the Wolfia team reviews and grants access.
Contact supportReport a vulnerability
Trust center by Wolfia: AI trust center & security questionnaire automation
Does your team answer security questionnaires too? Wolfia answers them for you and runs trust centers
Controls
Access control
Robust identity and permission safeguards prevent unauthorized system access and enforce least-privilege principles
Single sign-on support
Customers can enforce their own identity policies through SAML 2.0 and OpenID Connect, allowing corporate MFA, conditional access, and streamlined user lifecycle management.
Automated user provisioning
Directory sync lets customers provision, update, and deprovision their users automatically from their identity provider.
Role-based access control
Role-based access control maps permissions to job function so each user receives only the access they need.
Formal onboarding and off-boarding
New users receive documented approval before accounts are created and departing users have all access disabled within one business day, eliminating orphaned credentials.
Encrypted administrative access
Production environments may only be reached through approved encrypted channels, safeguarding credentials and session data in transit.
Annual access reviews
Documented reviews of all production accounts verify that privileges remain appropriate and any unnecessary access is removed.
Multi-factor authentication
Employee access to internal systems requires single sign-on with enforced multi-factor authentication, and customers can require their own identity provider for their users.
Data security
Encryption, retention and classification controls protect customer information throughout its lifecycle
Encryption at rest
Customer data, temporary files and backups are protected with strong AES-256 encryption whenever stored on disk.
Encryption in transit
Secure transport protocols are mandated for all external and internal transfers, preventing eavesdropping over public networks.
Data retention and deletion policy
Customer data, including encrypted backups, is purged within 90 days of contract termination or a verified deletion request, as committed in the Data Processing Agreement.
Full-disk workstation encryption
Company-issued laptops are required to use whole-disk encryption, preventing data loss if a device is lost or stolen.
Data classification scheme
Information is labeled as secret, confidential, internal, or public, enabling appropriate handling, retention, and disposal according to sensitivity.
Application security
A mature secure development lifecycle and continuous testing keep the platform resilient against software threats
Secure development policy
Documented standards embed security requirements throughout design, coding, testing, and deployment activities.
Static code analysis
Static code analysis runs automatically on every change before it can be merged.
Dependency and image vulnerability scanning
Dependencies and container images are automatically scanned for known vulnerabilities on every change, and patches are applied promptly.
Annual third-party penetration testing
Independent security experts test the web application and API at least annually. The most recent test closed with zero open findings after remediation, and the report is available under NDA.
Web application firewall
A managed WAF blocks common web threats and combined DDoS protection keeps the service available even during volumetric attacks.
Secret scanning and rotation
Secret scanning runs on every commit, and any exposed credential is rotated promptly.
Trusted container images
All application containers are built from approved sources and stored in a private registry to block malicious code insertion.
Deployment approval workflow
Changes reach production only through pull requests to a protected branch that must pass automated security and quality checks before they can be merged.
Infrastructure security
Layered cloud defenses harden the hosting environment against network and platform attacks
Automated scaling and load balancing
The platform automatically provisions resources and distributes traffic as usage grows, maintaining performance without manual intervention.
Encrypted backups with geographic redundancy
Encrypted backups run daily with continuous point-in-time recovery and are copied to a second geographic region so data can be restored after a regional outage.
Cloud threat detection
Cloud-native threat detection continuously analyzes account, network, and audit activity and alerts the security team.
Multi-zone redundancy
Production runs across multiple availability zones, with backups copied to a second region for disaster recovery.
Private network segmentation
Production systems run in private networks. Only required inbound ports are exposed, and databases and the cluster control plane are not reachable from the internet.
Baseline configuration enforcement
Infrastructure and platform configuration are defined as code, reviewed before deployment, and continuously reconciled against the approved state.
Incident response
Documented processes and regular drills ensure swift detection, containment and communication of security events
Incident response plan
Clear playbooks define roles, escalation paths and customer notification procedures for security events.
Annual incident simulations
Table-top and drill exercises test the plan each year, driving improvements from real-world lessons.
Real-time security alerting
Monitoring tools send immediate notifications to dedicated channels, ensuring swift human review of potential incidents.
Ticket-based incident tracking
All incidents are logged and tracked to closure, providing auditable evidence of timely remediation.
Evidence preservation procedures
All incident workflows include collecting and safeguarding logs and artifacts to support forensic analysis and reporting.
Root-cause analysis reviews
Post-incident reviews identify systemic issues and feed improvements back into the security program.
Dedicated incident response team
Trained personnel are on call to triage, contain, and communicate security incidents, ensuring rapid, coordinated action.
Compliance and auditing
Independent attestations, internal reviews and insurance demonstrate commitment to recognized frameworks
SOC 2 Type II report
A licensed CPA firm verified that controls for security, availability, and confidentiality were designed and operated effectively throughout the audit period.
Annual control self-assessments
Management reviews each security control yearly to verify effectiveness and document remediation actions.
Compliance management platform
A compliance management platform tracks control ownership and evidence collection for the SOC 2 program.
Annual policy review and approval
Senior management formally re-evaluates and signs off on the information security program every year to keep it current.
Coordinated vulnerability disclosure
Security researchers can report vulnerabilities to [email protected] under the published disclosure policy, and reports are triaged and remediated by the security team.
Cyber liability insurance
Cyber liability insurance is in place, and the certificate of insurance is available on request.
Monitoring and logging
Comprehensive, immutable telemetry enables rapid threat detection and forensic analysis
Centralized log management
Application and infrastructure logs are centralized and retained per policy for audit and investigation.
Continuous security monitoring
Automated tools analyze logs and metrics for anomalies, sending high-fidelity alerts to security staff.
Infrastructure performance alerting
Threshold-based alerts on availability and latency notify the on-call engineer.
Immutable audit trails
Administrative users cannot modify or delete their own activity logs, ensuring trustworthy evidence for investigations or audits.
Continuous vulnerability scanning
Workloads and container images are continuously scanned for known vulnerabilities and remediated according to risk.
Public status and metrics page
Customers can view real-time uptime, latency and historical incident data for full operational transparency.
Third-party management
Structured vetting and ongoing oversight reduce supply-chain and subprocessor risks
Vendor due-diligence assessments
Cost, functionality, security, privacy and financial health are evaluated before onboarding any critical provider.
Vendor inventory and risk ranking
All subprocessors are cataloged and scored based on data sensitivity and service criticality, guiding review depth and frequency.
Annual vendor reviews
Critical vendors and subprocessors undergo yearly reassessment to confirm they still meet contractual and security requirements.
Security due-diligence reviews
Contracts and SOC reports are annually examined to verify that vendor controls align with company security and privacy requirements.
Contractual confidentiality obligations
Agreements mandate that vendors uphold security, confidentiality, and privacy commitments consistent with customer expectations.
SOC report reviews for cloud host
Management reviews the cloud hosting provider's SOC 2 attestation each year to validate that complementary controls remain effective.
Zero data retention clauses for AI providers
Every AI provider processes customer data under zero-data-retention and no-training terms; none stores, reviews, or trains on customer data.
Subservice organization monitoring
The cloud hosting provider is the audited subservice organization in the SOC 2 Type II report. Other critical providers, including the AI inference providers, are covered by annual reviews of their SOC 2 Type II reports and data-processing terms. Additional providers are being evaluated for inclusion in the next audit period.
Subprocessor transparency list
An up-to-date list of authorized subprocessors is available to customers, supporting informed risk decisions and compliance obligations.
Privacy and data governance
Policies and processes uphold stringent privacy standards and empower customer control over information
High-standard data handling
All customer information is managed at the highest protection tier, avoiding lower-class segregation.
Confidentiality commitments in contracts
Customer agreements and the public trust center clearly state the company’s obligations for protecting private information.
Privacy policy and DPA
Comprehensive documents define roles, responsibilities, and safeguards for personal data processing in line with global regulations.
Customer-directed data deletion
Data is promptly erased upon customer request and automatically purged when contractual retention limits expire.
Data subject access procedure
Verified requests are fulfilled promptly, giving individuals control over their information and demonstrating regulatory compliance.
Data retention and disposal policy
Information is kept only as long as necessary, with secure deletion processes triggered by schedule or customer request.
No AI training on customer data
Customer content is never used to improve generalized models unless a bespoke contract explicitly authorizes it.
Transparent trust center disclosures
Security objectives, commitments and documentation are published so customers can easily verify privacy practices.
United States data residency
All processing, storage, and AI inference run in United States regions. An alternate storage-at-rest location can be arranged on request under an enterprise agreement; AI inference remains in US regions.
Employee security
People-focused safeguards ensure staff act as strong defenders of customer data
Security awareness training
Every employee completes training at hire and annually thereafter to stay current on threats and responsibilities.
Background screening
Interview, reference, and other checks are completed before onboarding to verify trustworthiness relevant to job duties.
Confidentiality agreements
Employees and contractors formally commit to protecting proprietary and customer information.
Standards of conduct acknowledgment
Employees must read and sign the code of ethics and information security program on hire and annually thereafter.
Centrally managed devices
Company devices are centrally managed with enforced disk encryption, screen lock, and automatic updates.
Formal performance accountability
Security responsibilities are embedded in job descriptions and annual reviews, ensuring individual accountability for control adherence.
Business continuity
Proven recovery capabilities minimize downtime and data loss during disruptive events
Documented BC/DR plan
A comprehensive continuity strategy defines procedures, roles and recovery objectives for critical services.
Annual recovery testing
Backup restores and continuity exercises are run at least annually and measured against the 24-hour recovery objective.
Risk mitigation planning
The organization identifies disruption risks and develops mitigations as part of its broader risk management program.
AI governance
Contractual, technical and procedural controls ensure responsible and secure use of artificial intelligence
Zero-retention model providers
Foundational model partners are contractually bound to discard all prompts and outputs after processing and to prohibit human review.
US-only AI processing
Inference workloads run within United States regions, helping customers satisfy strict data-residency or export-control requirements.
Risk management
Structured assessments identify, prioritize, and drive remediation of threats across the organization.
Annual enterprise risk assessment
Management documents threats, impact and mitigation strategies at least once per year to guide control priorities.
Formal risk management program
Documented methodology identifies, scores, and tracks risks, ensuring mitigation strategies receive appropriate resources.
Quarterly security risk reviews
A cross-functional team reassesses emerging risks each quarter to keep the program aligned with a changing landscape.
Fraud risk assessment
Evaluations consider incentives, opportunities, and potential fraud scenarios, embedding anti-fraud measures into the control framework.
Risk-based control selection
New controls are chosen and adapted based on quantified risk ratings, ensuring resources focus on greatest exposures.
Documentation
Featured
Web Application and API Penetration Test Report
Certificate of Liability Insurance
Wolfia Architecture Diagram
Wolfia Platform Security Overview
SOC 2 Type 2 Report
Anthropic - Zero Data Retention
Open AI - Zero Data Retention
Certifications
SOC 2 Type 2 Report
VPAT 2.5 - WCAG 2.2 Level AA Accessibility Conformance Report
Security
Open AI - Zero Data Retention
Anthropic - Zero Data Retention
Web Application and API Penetration Test Report
Wolfia Architecture Diagram
Wolfia Platform Security Overview
Business Continuity and Disaster Recovery (Plans and Tested Evidence)
Privacy & Legal
Certificate of Liability Insurance
Master Subscription Agreement
Questionnaires
Wolfia - CAIQ
Cloud Infrastructure
Hosting, compute, storage, and managed services that run the Wolfia platform
Amazon Web Services · United States
Primary cloud-hosting and infrastructure platform and AI services
United States
AI & LLM Providers
Foundation model providers used for AI, and document understanding
Anthropic · United States
LLM inference via Claude API
United States
Google · United States
LLM inference (Gemini) via Vertex AI on Google Cloud, used only as a fallback
United States
Microsoft Azure · United States
API-based AI inference only (Azure OpenAI Service, Azure AI Foundry, Azure AI Document Intelligence). No customer data is hosted or stored on Azure infrastructure.
United States
OpenAI · United States
LLM inference via OpenAI API
United States
OpenRouter · United States
Routing of inference requests to OpenAI and Anthropic models only, with zero data retention enforced on every request; no other inference provider is involved
United States
Platform Services
Vendors that power authentication, customer integrations, background workflows, and transactional email
Hatchet · United States
Managed workflow orchestration
United States
Nango · United States
Unified OAuth broker that proxies authentication and data sync for customer-side integrations
United States
Resend · United States
Transactional email delivery
United States
Stripe · United States
Payment processing
United States
WorkOS · United States
Enterprise SSO and directory sync (SCIM)
United States
Observability & Analytics
Tools that monitor application health and usage to keep the service reliable and improve the product
PostHog · United States
Product and usage analytics
United States
Sentry · United States
Error tracking
United States
Loading content...
Updates
Overview