Compliance & Certifications

Enterprise-Grade Compliance

SplintAI maintains the highest standards of security, privacy, and compliance to protect your manufacturing data.

Certifications

Third-party validated certifications demonstrating our commitment to security and privacy

SOC 2 Type II

Issued by AICPA

Active

Annual audit of security, availability, processing integrity, confidentiality, and privacy

Last audit: January 2025

ISO 27001:2013

Issued by ISO

Active

Information security management system certification

Last audit: November 2023

ISO 27017:2015

Issued by ISO

Active

Cloud security controls certification

Last audit: November 2023

ISO 27018:2019

Issued by ISO

Active

Protection of personally identifiable information in the cloud

Last audit: November 2023

Regulatory Compliance

Meeting and exceeding global data protection regulations

GDPR

Compliant

General Data Protection Regulation

Comprehensive data protection and privacy regulation for EU citizens

European Union
Key Features
  • Data Processing Agreements (DPA)
  • Right to erasure (Right to be forgotten)
  • Data portability
  • Privacy by design
  • Appointed Data Protection Officer

CCPA

Compliant

California Consumer Privacy Act

Privacy rights and consumer protection for California residents

California, USA
Key Features
  • Consumer data access rights
  • Opt-out mechanisms
  • Data deletion capabilities
  • Privacy policy transparency
  • Annual privacy training

HIPAA

Ready

Health Insurance Portability and Accountability Act

Protection of sensitive patient health information

United States
Key Features
  • Business Associate Agreements (BAA)
  • PHI encryption and access controls
  • Audit logging and monitoring
  • Employee HIPAA training
  • Incident response procedures

Security Practices

Comprehensive security measures across all aspects of our platform

Data Security

  • End-to-end encryption (AES-256)
  • Encryption at rest and in transit
  • Secure key management (HSM)
  • Data classification and handling
  • Regular security assessments

Access Control

  • Multi-factor authentication (MFA)
  • Role-based access control (RBAC)
  • Single Sign-On (SSO) support
  • Regular access reviews
  • Privileged access management

Infrastructure

  • AWS SOC-compliant infrastructure
  • Multi-region redundancy
  • DDoS protection
  • Network segmentation
  • 24/7 security monitoring

Operational

  • Security awareness training
  • Background checks
  • Incident response team
  • Vulnerability management
  • Third-party risk assessment

Industry Standards

SplintAI aligns with and implements leading industry security frameworks and standards to ensure the highest level of protection for your data.

NIST Cybersecurity Framework
Aligned
CIS Controls
Implemented
OWASP Top 10
Protected
PCI DSS
Level 1 Compliant

Privacy by Design

Privacy and security are built into every aspect of our platform from the ground up, not added as an afterthought.

  • Data minimization principles
  • Privacy impact assessments
  • Regular privacy training
  • Transparent data practices
Read Privacy Policy

Visit Our Trust Center

Access detailed security documentation, audit reports, and compliance certificates in our comprehensive Trust Center.