Secure by design
GriffinIQ handles controlled technical data for defense programs. Security and data sovereignty are foundational to how we build, not features bolted on later.
US-based infrastructure, data, and AI
All infrastructure, databases, and AI/LLM processing run on US-based cloud, operated from California. We do not use offshore processing or route controlled technical data outside the United States.
No foreign national access
Access to customer data is restricted to authorized US persons. We maintain access controls designed to support ITAR handling requirements.
Encryption in transit and at rest
Customer data is encrypted in transit (TLS) and at rest. BOM data submitted for a free scan is deleted after analysis.
No third-party AI training on your data
We do not use third-party AI providers to process your BOM data, and your data is never used to train external models.
On-premises and air-gapped deployment
Available for on-premises and air-gapped secure environments, for programs that require data to stay inside your own boundary.
Government cloud portable
Architected to be portable to AWS GovCloud (US) and equivalent government cloud environments.
Certifications & registrations
- SOC 2 Type II In progress
- ITAR Registration In progress
We're transparent about where we are. As certifications are completed, this page will be updated to reflect current status.
Reporting a vulnerability
If you believe you've found a security issue, please email [email protected]. We take reports seriously and will respond promptly.