Security & Trust

Enterprise-grade security

Your data is encrypted both in transit and at rest, using the most robust encryption standards. Built for the compliance requirements of regulated lenders.

SOC 2 Type II compliance seal
SOC 2 Type IIIn progress
ISO 27001 compliance seal
ISO 27001ISMS certified
GDPR compliance seal
GDPREU data residency
CCPA compliance seal
CCPACalifornia privacy
Trust architecture

Controls you can inspect, not claims you have to trust

Encryption · tenant keys
AES-256At rest
TLS 1.3In transit
Key rotationEvery 90 days
Key custodyHSM-backed
Field-levelPII + terms
Documents are decrypted only inside your tenant scope.

Encryption

TLS 1.2+ in transit and AES-256 at rest, with HSM-backed keys rotated on a fixed schedule.

Identity · SSO directory
Sign-in policySAML enforced
MFA on
OIDCConnected
SCIM provisioningLive
Role model7 scoped roles
DeprovisioningUnder 60 seconds

Identity & access

SAML, OIDC and SCIM with scoped roles, enforced MFA and deprovisioning in under a minute.

Isolation · tenant boundary
Data boundary

No borrower record leaves its tenant

Meridian fund tenantIsolated
Halden fund tenantIsolated
Cross-tenant queryBlocked
Every request is scoped by tenant before it reaches storage.

Tenant isolation

Every request is scoped to your tenant before it reaches storage. Cross-tenant access is impossible by design.

Audit trail · immutable
SAML session verified09:12
System
Document decrypted · tenant scope11:40
R. Alvarez
Read-only agent query16:02
MCP
Audit export generated17:26
M. Osei
Events retained7 years

Auditability

An immutable event trail for every test, approval, export and agent query, retained and exportable.

Deployment · options
AZ2 multi-tenant cloud
Single-tenant instance
Customer VPC deployment
Region pinning · EU / US
Data residencyYou choose
Uptime target99.9%
Current selectionSingle-tenant · EU

Deployment

Run on our cloud, a single-tenant instance, or inside your own VPC with region pinning.

Assurance · live posture
0Open findings
4mLast scan
24/7Monitoring
Penetration testAnnual · third party
Vulnerability scanContinuous
Incident responseDocumented
Evidence packet refreshed automatically for diligence requests.

Continuous assurance

Third-party penetration testing, continuous scanning and a live posture view your diligence team can read.

Deployment

Deploy the way your firm requires

From fully managed cloud to a private VPC inside your own perimeter, AZ2 fits the deployment model your risk and IT teams already run.

01

Multi-tenant cloud

Fastest to deploy. Logically isolated, SOC 2 Type II (in progress), live in days.

02

Single-tenant

Dedicated infrastructure and keys for firms with stricter isolation requirements.

03

Private VPC

Runs inside your cloud perimeter. Your network, your controls, our platform.

Auditability & access

A record for every action, a role for every seat

Role-based access controls decide who can act, and the audit trail records every action taken, by a person or an agent, the same record your examiners and LPs see.

Audit trail · Meridian Foods
Immutable logExportable
Priya Raman
Approved covenant waiver · Meridian Foods
logged
AZ2 Agent
Extracted revenue field from CreditPack.pdf
logged
James Ochoa
Exported audit log · Q2 board pack
logged
AZ2 Agent
Read-only sync · Box (128 files)
logged
Analyst
View & extract, no approvals
Credit officer
Approve, comment, export
Admin
Manage access & integrations
Sub-processors

Who else touches your data, and why

AZ2 relies on a short, disclosed list of vendors to run the platform and its AI features. This is a summary, the canonical, named list with purpose, data category, and region lives on the Legal page.

Amazon Web Services
Anthropic
OpenAI
Google Cloud Vertex AI
Snowflake
Twilio SendGrid
Datadog

Model inference (document classification, extraction and drafting) runs on enterprise cloud AI endpoints operated by Anthropic, OpenAI and Google Cloud Vertex AI, under terms of zero data retention and no training on customer data.

View the full sub-processor list on the Legal page →

Put AZ2 through your security review

SOC 2 report, pen test summary, DPA, and sub-processor list, available under NDA.

Request security packet