You are handing us your brand. We treat it that way.
Encryption in transit and at rest, tenant isolation enforced at the query layer, per-workspace keys, and a hard commitment that your content never trains a model. We hold no certifications yet, and we say so plainly below.
Where we actually stand today
Launchifyer is pre-launch and holds no third-party security certifications. We are not SOC 2 audited, not ISO 27001 certified, and we do not have a completed penetration test to share. When that changes we will name the auditor and the report date here.
We would rather lose a deal to a competitor with a real audit than win one on a certification we do not hold. If your procurement process requires an attestation today, tell us and we will be straight with you about the timeline.
What follows is how the platform is being built and what we commit to. Treat it as engineering intent, not as an audited control set.
Six commitments, no marketing language
Specifics your security reviewer can hold us to, written as commitments because that is what they are.
Encryption everywhere
- TLS 1.3 in transit, with HSTS and no legacy cipher suites
- AES-256 at rest across databases, object storage and backups
- Per-workspace encryption keys, rotated on a defined schedule
Access control
- SAML 2.0 and OIDC single sign-on, plus SCIM user provisioning
- Role-based permissions down to individual channels and campaigns
- Mandatory multi-factor authentication for every Launchifyer employee
Infrastructure
- Immutable infrastructure with no interactive access to production
- Every change ships through CI with a reviewed audit trail
- Least-privilege access, reviewed on a recurring schedule
Data isolation
- Logical tenant isolation enforced at the query layer
- EU data residency for storage and processing as a roadmap commitment
- Customer content is never used to train shared or third-party models
People
- Signed confidentiality terms before anyone gets access
- Security training for everyone who touches customer systems
- Access granted on need and revoked when a role changes
Testing
- Static analysis, dependency scanning and secret detection in CI
- Independent penetration testing planned ahead of general availability
- A coordinated disclosure process, live today (see below)
The questions every security team asks us
Generative systems introduce risks a traditional SaaS review does not cover. These are our answers, in writing.
Your content is not training data
Nothing you create, upload or connect will be used to train models — ours or a provider’s. We require zero-retention terms from every inference provider we integrate.
Every generation is attributable
Each asset records the model, prompt, brand guardrails and human approver involved, so you can reconstruct exactly how a piece of content came to exist.
Guardrails are enforced server-side
Brand, legal and regulatory constraints are applied during generation rather than checked afterwards, so a non-compliant draft is never produced in the first place.
Humans hold the publish button
Approval gates are configurable per channel and per risk level. Nothing goes live without whoever your policy says must sign off.
Everyone who can touch your data
Our infrastructure and model providers are still being finalised, so we are not publishing a list we would have to rewrite.
We will publish the complete subprocessor list — each vendor, its purpose and its processing region — before the first customer workspace goes live, and we commit to giving customers 30 days' notice before adding a new one. If you need the current working list for a review in progress, ask and we will send it as it stands.
Request the current listFound something? Tell us.
We do not run a paid bug bounty yet, and we would rather say so than imply a reward we have not budgeted. What we do commit to: we read every report, we will acknowledge yours, and safe-harbour applies to good-faith research — we will never pursue legal action against a researcher who reports responsibly and gives us a reasonable window to fix the issue before disclosing.
security@launchifyer.com