Skip to main content
Trust & security

You are handing us your brand. We treat it that way.

Encryption in transit and at rest, tenant isolation enforced at the query layer, per-workspace keys, and a hard commitment that your content never trains a model. We hold no certifications yet, and we say so plainly below.

Where we actually stand today

Launchifyer is pre-launch and holds no third-party security certifications. We are not SOC 2 audited, not ISO 27001 certified, and we do not have a completed penetration test to share. When that changes we will name the auditor and the report date here.

We would rather lose a deal to a competitor with a real audit than win one on a certification we do not hold. If your procurement process requires an attestation today, tell us and we will be straight with you about the timeline.

What follows is how the platform is being built and what we commit to. Treat it as engineering intent, not as an audited control set.

Talk to us about a security review
How we build

Six commitments, no marketing language

Specifics your security reviewer can hold us to, written as commitments because that is what they are.

Encryption everywhere

  • TLS 1.3 in transit, with HSTS and no legacy cipher suites
  • AES-256 at rest across databases, object storage and backups
  • Per-workspace encryption keys, rotated on a defined schedule

Access control

  • SAML 2.0 and OIDC single sign-on, plus SCIM user provisioning
  • Role-based permissions down to individual channels and campaigns
  • Mandatory multi-factor authentication for every Launchifyer employee

Infrastructure

  • Immutable infrastructure with no interactive access to production
  • Every change ships through CI with a reviewed audit trail
  • Least-privilege access, reviewed on a recurring schedule

Data isolation

  • Logical tenant isolation enforced at the query layer
  • EU data residency for storage and processing as a roadmap commitment
  • Customer content is never used to train shared or third-party models

People

  • Signed confidentiality terms before anyone gets access
  • Security training for everyone who touches customer systems
  • Access granted on need and revoked when a role changes

Testing

  • Static analysis, dependency scanning and secret detection in CI
  • Independent penetration testing planned ahead of general availability
  • A coordinated disclosure process, live today (see below)
AI governance

The questions every security team asks us

Generative systems introduce risks a traditional SaaS review does not cover. These are our answers, in writing.

Your content is not training data

Nothing you create, upload or connect will be used to train models — ours or a provider’s. We require zero-retention terms from every inference provider we integrate.

Every generation is attributable

Each asset records the model, prompt, brand guardrails and human approver involved, so you can reconstruct exactly how a piece of content came to exist.

Guardrails are enforced server-side

Brand, legal and regulatory constraints are applied during generation rather than checked afterwards, so a non-compliant draft is never produced in the first place.

Humans hold the publish button

Approval gates are configurable per channel and per risk level. Nothing goes live without whoever your policy says must sign off.

Subprocessors

Everyone who can touch your data

Our infrastructure and model providers are still being finalised, so we are not publishing a list we would have to rewrite.

We will publish the complete subprocessor list — each vendor, its purpose and its processing region — before the first customer workspace goes live, and we commit to giving customers 30 days' notice before adding a new one. If you need the current working list for a review in progress, ask and we will send it as it stands.

Request the current list

Found something? Tell us.

We do not run a paid bug bounty yet, and we would rather say so than imply a reward we have not budgeted. What we do commit to: we read every report, we will acknowledge yours, and safe-harbour applies to good-faith research — we will never pursue legal action against a researcher who reports responsibly and gives us a reasonable window to fix the issue before disclosing.

security@launchifyer.com