Security & Compliance
Meeting and exceeding industry standards to protect your data with enterprise-grade security controls.
Continuous, tamper-proof internal audits—powered by our AI agent.
We run zero-knowledge, append-only compliance checks across SOC 2 and the frameworks on this page. Every audit is hash-chained, digitally signed, and independently verifiable—so findings can’t be altered after the fact. Reports are reviewed by our team and complement independent assessments.
How our internal audit works
What this means for you
Note: Our internal audits supplement (not replace) independent certifications or attestations. Where required (e.g., SOC 2 Type II), we continue to engage accredited third parties.
While we're in the final stages of our SOC 2 Type II audit, our policies and procedures are already built to meet—or exceed—the five Trust Services Criteria that underlie the framework.
Five Trust Services Criteria
Access Controls
Every engineer and operator is granted only the minimum permissions they need, enforced via role-based access and multi-factor authentication.
Network Protections
All systems sit behind firewalls, intrusion-detection systems, and strict egress filtering—so only authorized traffic ever reaches our infrastructure.
Redundancy & Monitoring
Our storage and compute clusters are geographically distributed. We run real-time monitoring and automatic failover to ensure your data and services stay online, even if a single region has issues.
Incident Response
We maintain a documented playbook and conduct quarterly drills to guarantee we can recover quickly from outages or attacks.
Change Management
All code and configuration changes go through a formal review process, automated testing, and staged deployment pipelines—so what runs in production is exactly what was approved.
Error-Handling
We log and track every exception, with dashboards and alerts to catch anomalies long before they turn into customer impact.
Encryption
Client-side AES-256 locks your files before they leave your device, and TLS 1.3 protects data in transit. We never persist decryption keys on our servers.
Data Segmentation
Customer data is logically segregated in our databases and storage buckets, preventing any accidental cross-tenant access.
Data Minimization
We collect only the information we need to run the service, and our privacy policy spells out exactly how—and why—we use it.
Access Reviews
We regularly audit internal logs and access reports to verify that personal information is only viewed by authorized personnel for legitimate business purposes.
Once complete, you'll be able to review our full SOC 2 report under NDA.
In the meantime, these controls are already in place and tested daily—so even before formal certification, you're getting the benefits of a SOC 2–grade security and compliance program.
Virtual Data Rooms (VDR) — Controls & Assurances
- Zero-knowledge handling: Documents are encrypted client-side before upload; SpeculaFree cannot access plaintext content.
- Access governance: Role-based permissions, view-only modes, download restrictions, link expiry and passcode gates minimise data exfiltration risk.
- Watermarking & deterrence: Per-viewer, time-stamped watermarks applied to previews and PDFs to discourage redistribution.
- Auditability: Every access, view and download is logged with timestamps and contextual metadata for investigations and reporting.
- Data minimisation: Only required metadata is processed to operate the room; you control retention and can revoke access at any time.
- Incident readiness: Exportable activity logs streamline internal reviews and third-party assessments.
- Customer responsibilities: As the data controller, you manage who gets access and what they can do; SpeculaFree provides the controls to enforce your policies.
Additional Compliance Standards
For those in the healthcare sector, Speculafree supports your HIPAA compliance efforts. We can sign a Business Associate Agreement (BAA) with covered entities, affirming our responsibilities to safeguard Protected Health Information (PHI). We implement all three types of safeguards: Technical, Physical, and Administrative.
Privacy by design is at the heart of Speculafree. For users subject to GDPR, we support data minimization, lawfulness, transparency, and the rights of data subjects. We have a GDPR-compliant data processing addendum and Standard Contractual Clauses in place for data transfers.
Speculafree helps meet requirements for financial professionals. Our service is part of your strategy to protect customer financial information under GLBA's Safeguards Rule. We can be configured to support data retention rules for FINRA/SEC compliance.