Home / Trust Center

Trust Center

Security, privacy, and trust at Innoveye.

We build and ship AI inside regulated, high-stakes enterprises, so security and privacy are designed into everything we do. This page summarizes our practices, our compliance roadmap, and the documents we can share with customers on request.

MFA enforced Encryption in transit & at rest Least-privilege access SOC 2 - planned ISO 27001 - roadmap
Compliance

Where we are, and where we are headed.

We are early and deliberately transparent about it. We operate to recognized security practices today and are building toward formal certification.

SOC 2

Planned. We are aligning our controls and evidence to pursue a SOC 2 examination.

ISO 27001

On the roadmap. Our information security program is structured with ISO 27001 in mind.

Privacy law

We operate in line with the Israeli Privacy Protection Law and support GDPR obligations where they apply.

Practices in place today

How we protect your data.

The controls we operate as a lean, forward-deployed engineering firm. Where we work inside your environment, your controls apply in addition to ours, and we follow the stricter of the two.

Access control

Least privilege and need-to-know, with access reviewed regularly and revoked promptly.

Multi-factor authentication

MFA enforced on business-critical accounts, including email, code, and cloud consoles.

Encryption

Data encrypted in transit with current TLS and at rest on company devices and services.

Data minimization

We prefer to work inside your environment rather than copy data out, and keep only what a task needs.

Incident response

A defined process to detect, contain, recover from, and report security incidents.

Secure development

Secrets kept out of code, dependencies kept current, and changes reviewed before they ship.

Documents

Policies and reports.

These documents are confidential. Request access below and we will share the current version with you by email, typically within one business day.

Information Security Policy

Our top-level security program and principles.

Locked

Access Control Policy

Least privilege, MFA, and account lifecycle.

Locked

Incident Response Policy

How we detect, contain, and report incidents.

Locked

Data Protection & Privacy Policy

Data classification, retention, and personal data.

Locked

Business Continuity & DR Policy

Resilience, backups, and recovery objectives.

Locked

Privacy Policy (website)

How our website handles visitor data. Publicly available.

View
Request access

Ask for a document.

Tell us who you are and what you need. We will review and share the current version by email, typically within one business day.