Skip to main content

Security and compliance

Security is a first-class requirement of the PostgresAI Platform, not an afterthought. This page covers our independent attestations and how we run security day to day.

Compliance and attestations

SOC 2® Type 2 attested — audited by Sensiba LLPSOC 2® Type 2 attested — audited by Sensiba LLPAICPA SOC for Service Organizations seal (SOC 2®)

The PostgresAI Platform has successfully completed a SOC 2® Type 2 examination for the Security and Availability Trust Services Criteria, performed by Sensiba LLP, covering the period March 4 – June 4, 2026.

The SOC 3® report is publicly available and can be downloaded below. The SOC 2 Type 2 report contains detailed control and testing information, is restricted use, and is shared with customers and prospects under NDA on request.

How we run security

Encryption
Data is encrypted in transit with TLS, and volumes holding customer data are encrypted at rest.
Backups and availability
Platform data is backed up on a regular schedule, with restores exercised as part of our availability commitments — one of the two Trust Services Criteria in the scope above.
Incident response
Incidents are triaged by the engineer on call, assigned a severity, and any incident that risks customer data triggers a customer alert within 24 hours.
Vulnerability management
Container images and dependencies are scanned continuously, and findings are tracked to remediation.

Full detail — architecture, customer data handling, and the security model for self-managed installations — is in the DBLab Platform security documentation.

Found a possible vulnerability? Email [email protected].

Request the SOC 2 Type 2 report

Tell us a little about you and we will send the report under NDA. Requests are answered by a person, not an automated download.

Submitting opens a pre-filled message in your email client.

No email client? Write to [email protected] with the same details and we will pick it up from there.