HomeLegal

Security & Trust Center

Last Updated: August 7, 2026

When implementing AI in the enterprise, security cannot be an afterthought. Maquana engineers intelligent systems from the ground up to meet the strictest compliance, data privacy, and infrastructural security requirements.

SOC 2 Type II Compliance

Our infrastructure and internal processes adhere to strict SOC 2 compliance standards, ensuring your data is handled with maximum security.

Zero-Retention APIs

We exclusively utilize enterprise APIs with zero-data-retention agreements, guaranteeing your proprietary data is never used to train public models.

Private Deployments

For maximum security, we can deploy LLMs and vector databases entirely within your Virtual Private Cloud (VPC) or on-premise infrastructure.

Role-Based Access (RBAC)

Our systems integrate seamlessly with your existing SSO (Okta, Entra ID) to enforce strict role-based access controls at the document level.

Infrastructure Security

  • Encryption in Transit: All data transmitted between clients and our services is encrypted using TLS 1.2 or higher.
  • Encryption at Rest: All stored data, including vector embeddings and document caches, is encrypted at rest using AES-256.
  • Vulnerability Scanning: We conduct continuous static application security testing (SAST) and dynamic application security testing (DAST).

Reporting a Vulnerability

We take security extremely seriously. If you believe you have found a security vulnerability in any Maquana system, please report it immediately to our security team. We ask that you do not publicly disclose the issue until we have had a chance to address it.

Contact our security team at security@maquana.com.