Security, compliance, and privacy in one place.
Your training logs contain your IP, your proprietary model architectures, and your training data. We treat them that way. Below is everything procurement, security, and IT need to evaluate Denpex. Request any document under NDA. We typically respond within one business day.
Compliance status
SOC 2 Type II planned. Our controls are mapped to the 2017 Trust Services Criteria (below); we'll publish the report once the examination completes.
Standard DPA countersigned electronically, typically same-day. EU SCCs included for international transfers.
BAA available for healthcare and life-sciences customers on Data Center. Configurable PHI masking rules enforced by the agent.
Independent third-party penetration testing planned. We'll publish an executive summary once it's complete.
Consensus Assessments Initiative Questionnaire v4 completed and available on this page.
Live list below. Sub-processor changes are announced 30 days in advance via email and the changelog RSS.
Data flow
A single diagram, end to end. Logs leave your cluster only after masking runs client-side, and on Scale+ the diagnosis engine runs inside your VPC.
Cross-fleet failure intelligence contributes only anonymized, aggregated signatures to the shared pool (k-anonymity floor, k = 5), see the cross-tenant data handling disclosure.
Shared responsibility
What's our job and what's yours. Standard cloud model, called out plainly.
SOC 2 controls in place
The control set we map to the 2017 Trust Services Criteria.
Information security policies reviewed annually. Security officer: security@denpex.com.
Internal Slack, GitHub, 1Password, Google Workspace. Quarterly access review.
Annual risk register; reviewed quarterly by leadership. Vendor risk assessed at onboarding and yearly thereafter.
Cloudflare Workers logs with Logpush to R2 (30-day retention), D1 audit trail for billing and team changes, Sentry for frontend errors. Real-time tail for critical failures; daily error digest to team Slack.
Change management via GitHub PRs with required reviews; deploys via CI; rollback within 60 seconds.
SSO enforced; MFA required for all production access. Production data is accessible only via short-lived, audited credentials.
Backups nightly, 30-day retention. DR runbook tested annually. RTO 4h / RPO 1h for control-plane data.
All production changes go through a PR with at least one reviewer; CI runs lint, typecheck, and unit tests on every commit.
Vendor security reviews at procurement.
Our live status page is at denpex.com/status.
Logs deleted after diagnosis on Free/Team; in-VPC agent option on Scale+; AES-256 at rest, TLS 1.3 in transit.
DPA on request. Data subject access & deletion requests honored within 30 days. Sub-processor list below.
Sub-processors
Every third party that processes customer data on Denpex's behalf. We give 30 days' notice of changes via email and our changelog RSS.
| Sub-processor | Purpose | Data region | Vendor-attested certifications |
|---|---|---|---|
| Cloudflare | Hosting, edge network, KV, D1, Workers, R2 | Global edge (data stored in your selected region) | SOC 2 Type II, ISO 27001, PCI DSS |
| Stripe | Payment processing and subscription management | US, EU (by customer selection) | PCI DSS Level 1, SOC 2 Type II, ISO 27001 |
| SendGrid (Twilio) | Transactional email (signups, alerts, contact replies) | US, EU (region selectable) | SOC 2 Type II, ISO 27001, HIPAA-eligible |
| Google (Gemini, OAuth, Search, YouTube) | Primary AI log analysis via the Denpex proxy (training logs may contain hostnames, paths, and environment details); authentication identifiers; and log-derived search queries sent to Google Search or YouTube when those optional research paths are used | Provider-dependent | Vendor-attested; scope varies by service |
| Anthropic (Claude) | AI-powered log analysis and failure diagnosis, fallback model path via the Denpex proxy when the primary model is rate-limited | US | SOC 2 Type II |
| DeepSeek | AI-powered log analysis, secondary fallback when the primary proxy is exhausted | Provider-dependent | Vendor-attested (provider-dependent) |
| Groq | AI-powered log analysis, optional fallback provider | Provider-dependent | Vendor-attested; review the configured service terms |
| TokenHub | AI-powered log analysis, optional fallback routing service | Provider-dependent | Vendor-attested; review the configured service terms |
| PostHog | Product analytics (opt-in via cookie consent) | US, EU | SOC 2 Type II |
| GitHub | Source code hosting, CI/CD, issue tracking, and optional issue research using log-derived query text | US (data in your selected region) | SOC 2 Type II, ISO 27001 |
| Slack (optional) | Alert delivery when customer configures Slack as a channel | US | SOC 2 Type II, ISO 27001, FedRAMP Moderate |
| PagerDuty (optional) | Incident routing when customer configures PagerDuty as a channel | US, EU | SOC 2 Type II, ISO 27001, HIPAA |
| Vonage / Nexmo (optional) | SMS alert delivery, preferred SMS provider when configured | US, EU | Vendor-attested |
| Twilio (optional) | SMS / iMessage alert delivery, fallback SMS provider when Vonage is not configured | US, EU | SOC 2 Type II, ISO 27001, HIPAA-eligible |
| Stack Exchange | Optional community search using log-derived query text | Provider-dependent | Vendor-attested |
| Algolia (Hacker News search) | Optional Hacker News index search using log-derived query text | Provider-dependent | Vendor-attested |
| Y Combinator (Hacker News) | Optional community-result retrieval using log-derived query text | Provider-dependent | Vendor-attested |
| Lobsters | Optional community search using log-derived query text | Provider-dependent | Vendor-attested |
| Optional community search using log-derived query text | Provider-dependent | Vendor-attested | |
| DEV Community (Forem) | Optional developer-community search using log-derived query text | Provider-dependent | Vendor-attested |
| GitLab | Optional issue and code search using log-derived query text | Provider-dependent | Vendor-attested |
| Exa | Optional web research using log-derived query text | Provider-dependent | Vendor-attested |
| OpenCode | Optional developer research using log-derived query text | Provider-dependent | Vendor-attested |
| Discord | Optional community-result retrieval and linked attachment delivery | Provider-dependent | Vendor-attested |
Responsible disclosure
Found a vulnerability? Please email security@denpex.com with reproduction details. We acknowledge within one business day and aim to ship a fix within 30 days for valid issues.
Security contact & policy: /.well-known/security.txt
Request a document
Tell us which document you need and we'll send it under NDA, signed electronically.