Third Party Index

Snapshot 40773

Document
Trust center
URL
https://factorylabs.ai/trust
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
623966 bytes
SHA-256 (raw)
d2a8baa1aa76e5be9ccaf0311b1ffbae7910da05d8f46bfadfb502d073e095a9
SHA-256 (normalized text)
832807f5e989989ccb9ca402035b04b67db03143cde6ab125a987e54feafc675

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
SOC 2 Type I - All 5 TSCPCI DSS CompliantSAQ-ACSA STAR Level 1publishedOWASP ASVS L1
Security and Compliance,trace each claim to its source
Every control, sub-processor and admin console is enumerated below with a pointer to the runbook or code path that backs it. The full Evidence Pack is available under NDA.
Request Evidence PackBrowse public details
TSC controls covered
61
of 61 (100%); 2 out of scope
Sub-processors enumerated
22
19 SOC 2 Type II certified
Admin consoles MFA-enforced
13
of 13 attested
SOC 2 Type I · All 5 TSC
SOC 2 Type I Report Issued August 12, 2026
No exceptions. Security, Availability, Confidentiality, Privacy and Processing Integrity.
Open SOC 2
CSA STAR Level 1 · published
CSA STAR Level 1
Cloud Security Alliance STAR Registry listing since 2026-08-06. Full CAIQ v4.1 self-assessment (283 questions) is public on the registry; the CSA STAR tab below summarizes domains for quick procurement review.
View STAR Registry listingBrowse CSA STAR tab
What we mean when we say “trustworthy”
The report is one artifact. The six pillars below are structural decisions an auditor can verify in code. Together they answer the standard SOC 2 / CAIQ / SIG questionnaire shape without inventing answers.
Schema-per-tenant isolation
Every organization gets its own Postgres schema (`org_<slug>`). Cross-tenant access is impossible by construction: every query runs through `withTenant()` which sets `search_path` to the calling org. Audited by a regression test that confirms a tenant A request is rejected when authenticated as tenant B.
src/lib/db/tenant.ts, src/__tests__/cross-tenant/
Encrypt at rest, in transit, and at the per-record layer
TLS 1.3 only on the wire (1.0/1.1 rejected at handshake). Neon-native AES-256-GCM at rest. Per-tenant DEK with AES-256-GCM HKDF-SHA-512 wrap for OAuth tokens, API keys, and webhook secrets: leaked DB rows are useless without the per-tenant key.
next.config.ts, src/lib/db/crypto.ts, src/lib/integrations/crypto.ts
MFA enforced across administrative consoles; quarterly reverification program in progress
Vercel (including factorylabs.ai DNS), Neon, GitHub, Twilio, Resend, Anthropic, OpenAI, Deepgram, Databricks, Stripe: MFA is enforced (TOTP or hardware key) on every door into tenant data. End-user MFA enforced by the upstream IdP (Google Workspace / Entra / GitHub). Quarterly reverification of all admin-console attestations is in progress.
docs/trust/identity-mfa-attestation.md
Zero training on tenant prompts
Anthropic Claude, OpenAI GPT, Deepgram STT: every LLM/STT call is made with the provider's zero-data-retention contract enabled. No prompt or transcript is stored beyond the 30-day abuse-detection window. Contractually enforced via enterprise terms.
Provider enterprise contracts (request via security@)
All sub-processors enumerated under Article 28 GDPR
Every third party that stores, processes, or transmits tenant data is listed with purpose, region, and compliance posture. 30-day advance email notification for changes (Enterprise tier). No silent vendor swaps.
docs/trust/sub-processors.md
Audit trail of every privileged action
Super-admin actions, impersonation events, integration changes, and gated evidence-pack downloads each write an append-only log row with actor email, IP, user agent, and target. Never deleted; queryable by tenant DPO via security@.
src/lib/db/schema.ts (audit_log, super_admin_audit_log, trust_access_log)
Gated · NDA
Get the full Evidence Pack
The pack contains everything on this page plus the operational runbooks (incident response, secret rotation, tenant offboarding) and the latest pentest report. Released to you under mutual NDA; each PDF is watermarked with your email and download timestamp.
SOC 2 controls catalog (CC1–CC9, A1, C1, P)
Sub-processor inventory (Article 28 GDPR)
Identity & MFA attestation (15 consoles)
Operational runbooks
Latest pentest report
Request accessEmail security@
Approval time
≤ 1 business day
Allowlisted customer / partner domains are auto-approved on email verification.
How access works
1. Submit your work email + intended use.
2. Get a 6-digit code in your inbox.
3. View tabs + download watermarked PDFs.
Factory Labs Inc. · 8 The Green Ste B, Dover, DE 19901
security@factorylabs.aiRequest Evidence PackSystem statusSecurity overview →