Skip to content
APH·SEC-001Trust & Security
REV A

Trust & Security

Apiphany builds a physics-first AI platform for data-driven decision-making in hardware engineering and manufacturing. We operate under strict security controls so that our clients in highly regulated & sensitive industries can innovate with confidence.

SOC 2 Type II · CERTIFIEDISO 27001:2022 · CERTIFIEDNIST SP 800-171 · ALIGNEDITAR / EAR Aware · ALIGNED
APH·SEC-002Our Commitment
REV A

Security is the cornerstone of everything we build. Apiphany serves clients across aerospace, automotive, defense, industrial, medical, and advanced manufacturing industries where protecting intellectual property, controlled technical data, and proprietary engineering information is non-negotiable. Our security program is independently audited, continuously monitored through our compliance partner Secureframe, and aligned with the frameworks that matter most to regulated enterprises.

APH·SEC-003Certifications & Compliance Frameworks
REV A

Certifications & Compliance Frameworks

Apiphany maintains active certifications and documented compliance with the industry's most rigorous security standards.

CERTIFIED

SOC 2 Type II

Independently audited against all five AICPA Trust Service Criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy. Our Type II report validates the operating effectiveness of controls over a sustained observation period, covering access management, encryption, change control, incident response, and data lifecycle governance.

CERTIFIED

ISO/IEC 27001:2022

Certified to the current edition of the international standard for Information Security Management Systems (ISMS). Our certification scope encompasses organizational, people, physical, and technological controls across 93 Annex A requirements — including risk assessment, asset management, supplier relationships, and continuous improvement.

ALIGNED

NIST SP 800-171

Fully compliant with all 110 security requirements for safeguarding Controlled Unclassified Information (CUI). Our implementation spans all 14 control families, from access control and audit accountability through system and communications protection, personnel security, and supply chain risk management.

COMPLIANT

GDPR & CCPA

Our data processing practices comply with the EU General Data Protection Regulation and the California Consumer Privacy Act. We maintain documented Data Processing Agreements, support data subject access and deletion requests, and enforce purpose limitation and data minimization principles.

APH·SEC-004Export Control Compliance
REV A

Export Control Compliance

Apiphany serves clients in defense, aerospace, and dual-use manufacturing sectors. We maintain rigorous awareness of U.S. export control regulations and architect our platform to support client compliance obligations.

ITAR
International Traffic in Arms Regulations

The International Traffic in Arms Regulations govern the export and handling of defense-related technical data. Apiphany supports ITAR-regulated clients through:

  • U.S.-based infrastructure deployment options (GCP Government Cloud, Azure Government Cloud, AWS GovCloud)
  • Access controls scoped to business needs
  • Segregated environments for ITAR-controlled technical data, including design files, engineering specifications, and manufacturing process data
  • Audit logging and data lineage tracking for all controlled information
  • Encryption in transit and at rest
EAR
Export Administration Regulations

The Export Administration Regulations govern dual-use items and technology. Apiphany addresses EAR compliance through:

  • Platform architecture that supports data residency requirements and prevents unauthorized deemed exports
  • Validated encryption for data transmission and storage
  • Classification awareness for dual-use engineering and manufacturing data
APH·SEC-005Cloud Infrastructure
REV A

Cloud Infrastructure

Apiphany provides flexible, secure deployment options on infrastructure that meets the most stringent federal and industry requirements.

Azure Government Cloud

AWS GovCloud (US)

FedRAMP-authorized locations

Government cloud environments provide physically isolated, U.S.-jurisdiction data centers operated exclusively by screened U.S. persons meeting the requirements of ITAR, EAR, NIST, and federal acquisition regulations.

APH·SEC-006Security Controls
REV A

Security Controls

Our security program implements defense-in-depth across every layer of the organization — from infrastructure and code to people and process.

Access Control

  • Role-Based Access Control (RBAC) enforcement
  • Principle of least privilege with periodic access reviews
  • Multi-factor authentication (MFA)
  • SSO integration

Data Protection

  • Enterprise-Grade encryption at-rest and in-transit
  • Validated cryptographic modules
  • Data classification and handling policy (Public, Internal, Confidential, Restricted)
  • Secure key management with automatic rotation
  • Data retention and secure disposal

Infrastructure Security

  • Network segmentation and micro-segmentation
  • Next-generation firewalls and intrusion detection/prevention
  • Continuous infrastructure monitoring and alerting
  • Hardened system baselines
  • Immutable infrastructure with automated patching

Audit & Accountability

  • Comprehensive audit logging across all systems and data access
  • Tamper-evident, centralized log management and SIEM integration
  • Automated anomaly detection and alerting
  • Log retention aligned with regulatory requirements
  • Regular log review and access monitoring

Personnel Security

  • Background checks for all personnel
  • Secure onboarding and offboarding procedures
  • Visitor management and physical access controls

Vendor & Supply Chain

  • Formal vendor risk management program
  • Third-party security assessments prior to onboarding
  • Ongoing monitoring of critical services
APH·SEC-007Product & Application Security
REV A

Product & Application Security

Security is embedded into every stage of our software development lifecycle, from design through deployment and monitoring.

Secure Development

  • Secure SDLC with security requirements
  • Mandatory code review and analysis
  • Dependency scanning and software composition analysis
  • Formal change management and release approval process

Vulnerability Management

  • Annual third-party penetration testing
  • Continuous automated vulnerability scanning
  • Responsible disclosure program
  • Risk-based remediation SLAs
APH·SEC-008AI & Data Platform Security
REV A

AI & Data Platform Security

As an AI platform purpose-built for hardware engineering, Apiphany implements additional controls specific to machine learning systems and sensitive engineering data.

Model Integrity

Training data validation, model versioning with rollback, and inference monitoring protect against data contamination, model drift, and adversarial manipulation.

Intellectual Property Protection

Strict tenant isolation, access-controlled model distribution, and data lineage tracking ensure proprietary engineering data and trade secrets remain protected at every stage of the pipeline.

Data Sovereignty

Configurable data residency controls allow clients to specify geographic boundaries for data storage and processing, supporting compliance with ITAR, EAR, and jurisdictional requirements.

Tenant Isolation

Single-tenant segmentation for all compute & storage resources; ensures that data, models, and configurations are fully isolated with no contamination or spillage risk.

APH·SEC-009Data Privacy
REV A

Data Privacy

Apiphany maintains a comprehensive data governance program that addresses collection, use, retention, and disposal of personal and client data. Our privacy practices are aligned with GDPR and CCPA requirements, including documented Data Processing Agreements, data subject rights fulfillment processes, cross-border transfer safeguards, and privacy-by-design principles integrated into product development. Data classification policies ensure that confidential and restricted information is accessible only to authorized personnel with a documented business need.