What we hold โ and what is coming.
Certifications are not promised post-contract at Provenance AI. SOC 2 Type II certification is a pre-contract requirement โ no lab signs a primary agreement until the certification is in hand and the audit report is on file.
Why shared infrastructure is a
structural failure, not a risk.
The Mercor breach did not happen because of a sophisticated attack. It happened because all clients shared the same infrastructure. A compromised dependency in one environment had direct access to every client's data simultaneously. This is not a security failure that better monitoring prevents โ it is an architectural choice that makes cascade failure inevitable.
At Provenance AI, every client lab operates in a completely separate cloud environment. Not a separate VPC. Not a separate subnet. A separate cloud account with separate billing, separate access controls, separate encryption keys, and separate audit logs. The isolation is enforced at the infrastructure provider level โ not at the application level where it can be bypassed.
Isolated Vault Instance
Separate Encryption Keys
Isolated Vault Instance
Separate Encryption Keys
Isolated Vault Instance
Separate Encryption Keys
All inter-tenant communication: physically disabled
Every control. Every status.
No omissions.
The following table documents every primary security control in the Provenance AI architecture. Labs receive this document before any contract is signed, not after.
| Control Category | Specific Control | Implementation | Status |
|---|---|---|---|
| Supply Chain | Software Bill of Materials (SBOM) | Every production dependency documented and approved before use. Snyk automated scanning on every pull request. Daily CVE database checks against all running packages. | Live |
| Supply Chain | Dependency lockfiles enforced | No ad-hoc package installation in any environment. All dependency changes require security review gate before merge. Direct response to LiteLLM-style supply chain attacks. | Live |
| Identity & Access | Zero-trust network architecture | Every internal service requires explicit authentication. No implicit trust based on network location. MFA required for all internal systems. | Live |
| Identity & Access | Least-privilege access control | Role-based access with zero standing access to client data. Access is time-limited and requires explicit justification for each session. | Live |
| Encryption | Data at rest โ AES-256 | All client training data encrypted at rest. Keys managed in client-isolated HashiCorp Vault instances. Keys never touch application code. | Live |
| Encryption | Data in transit โ TLS 1.3 | TLS 1.3 minimum on all data transmission. TLS 1.2 and below explicitly disabled. Certificate pinning on all client-facing endpoints. | Live |
| Client Isolation | Separate cloud accounts per client | Each lab runs in a dedicated AWS, GCP, or Azure account. Separate billing, separate IAM, separate VPCs. Cross-account network routing disabled at provider level. | Live |
| Audit & Logging | Immutable audit logs | All data access, annotation, and modification events logged to immutable S3 + CloudTrail. Logs cannot be altered or deleted by any internal actor. | Live |
| Vulnerability Management | Penetration testing | Annual third-party penetration test by an independent firm. Results shared with co-pilot labs' security teams. Critical findings trigger 48-hour remediation SLA. | Annual |
| Compliance | GDPR data residency | EU data residency options for labs with European regulatory obligations. No EU personal data leaves EU AWS/Azure regions without explicit written authorization. | Q3 2026 |
| Compliance | FedRAMP readiness | Formal FedRAMP authorization process initiated in Year 2. Required for labs pursuing US government AI contracts through Microsoft and Amazon channels. | Year 2 |
Every promise is a
contract term.
Security SLAs at Provenance AI are written into every primary contract with financial penalties for breach. These are not vendor commitments that evaporate when something goes wrong โ they are enforceable obligations.
Download the Security Overview PDF
A one-page summary of our security architecture, certifications, and SLAs โ formatted for distribution to your security and legal teams.