Public Trust Center
Trust & security posture
Ironframe is a governance product, so its own control environment is documented here for prospect diligence. This is design-partner diligence material — not legal advice and not a substitute for an executed DPA.
Certification status (accurate)
Ironframe is not currently represented as SOC 2 certified. Diligence materials include SOC 2-aligned control narratives, technical measures, and architecture boundaries documented for design-partner review. Do not infer completed external attestation from marketing language.
Published diligence artifacts
Data Processing Addendum (DPA) Framework
Processor obligations, security measures, breach notification, and audit cooperation.
View artifact →Corporate Subprocessor List
Vercel, Supabase, Resend, Stripe, Google Gemini, Electricity Maps — purpose and data categories.
View artifact →Single-Region Data Residency & Infrastructure Sovereignty
Single-region Supabase anchor, tenant enclave isolation, and v0.1.0-ga-epic17 boundaries.
View artifact →
AI-use boundary
Where model inference is used (documented subprocessor: Google Gemini), prompts are scoped to de-classified telemetry for narrative synthesis. Human review and approval remain part of operator workflows. AI output is not a substitute for attested control evidence.
Product-claim boundaries
- No invented customer logos or implied customer endorsements.
- Demo tenants (including Medshield, Vaultbank, Gridcore labels) are internal/sandbox fixtures — not customers.
- Certification and assurance status is stated only when earned; roadmap items are labeled as roadmap.