Security & Trust

Trust, earned in the audit trail.

ThreatLens is built on data residency, auditability, human authority, and enterprise-grade controls, at its foundation, not bolted on after the fact. Every conclusion is evidence-backed, every action is logged, and your data stays under your governance.

SOC 2 Type II in progress On-premise & air-gap ready BYOK encryption support No training on customer data
Security overview

Secure at every layer.

ThreatLens is built security-first across infrastructure, application, data, and AI. Sensitive security telemetry is encrypted in transit and at rest, access is least-privilege by default, and every action is written to a tamper-evident trail, whether you run in our cloud or your own.

Infrastructure security

Hardened, continuously patched infrastructure with encryption everywhere (AES-256 at rest, TLS 1.3 in transit).

Application security

Secure SDLC, dependency scanning, and regular third-party penetration testing.

Tamper-evident logging

Every decision, tool call, and action is logged to an immutable audit trail.

Deployment models

Deploy where your data must live.

Public Cloud

Fully managed multi-tenant SaaS. Fastest path to value, continuously updated, with regional data residency options.

Private Cloud

Dedicated, single-tenant deployment in your own cloud account, your VPC, your controls, your isolation.

On-Premises

Self-hosted in your datacenter. Air-gap compatible for fully isolated, regulated environments.

Access controls

Least privilege, by default.

RBAC

Granular role-based access control. Scoped, least-privilege roles per user and per tenant.

Authentication

SSO via SAML 2.0 and OIDC, with session controls and enterprise identity provider integration.

MFA

Multi-factor authentication enforced by policy across all access paths.

Data handling

Your data stays yours.

Customer data ownership

You own your data. ThreatLens never sells it and never trains models on customer data.

Isolation

Strong tenant isolation with encryption at rest and Bring-Your-Own-Key (BYOK) support.

Retention

Configurable retention and deletion policies. Data is purged on request and on contract termination.

AI Governance

AI you can actually approve.

AI governance is foundational to ThreatLens. Our agents accelerate investigations without ever taking control away from your analysts, and every conclusion is backed by evidence you can inspect.

Human-gated response

ThreatLens recommends; your analysts decide. Every containment, remediation, or destructive action requires explicit human approval, automation never acts unilaterally.

Evidence-backed reasoning

Every verdict and recommendation is grounded in source telemetry, intelligence, and observed activity, with supporting evidence, gaps, and confidence surfaced, never hidden.

Auditability

Every agent decision, tool invoked, and action taken is written to a tamper-evident audit log, so any investigation can be reconstructed from first signal to closure.

Explainability

No black-box verdicts. Reasoning is transparent and inspectable, with clear citations back to the evidence. Model cards available on request.

Compliance & policies

A live compliance posture.

View our current certifications, security reports, and policies in our Trust Center, kept continuously up to date.

SOC 2 Type II (In Process) Penetration tested
View our Trust Center →

Powered by Vanta · live certifications & reports

Contact security team

Report a vulnerability.

We take security disclosures seriously. If you've found a vulnerability or have a security concern, reach our security team directly, we respond to every report.

security@thethreatlens.com