Security you can verify.
S32 Technologies serves missions where security has to be demonstrated rather than asserted. This is the whole posture in one place: the frameworks our controls are built to, the boundaries we hold, and who we will and will not supply.
The trust section
Eligibility
Who we will supply, the eight checks every engagement passes, and the six outcomes the review can reach.
Responsible Use
Capability is not permission. How we decide what to build, whom to supply, and when to stop.
Export Controls
The regime we operate under, and why a demonstration is treated the same as a delivery.
Security & Data Handling
Where data lives, who can reach it, how support access works, and who else is in the path.
Civil Liberties
Interception touches people who are not its target. What bounds that, and what we will not build.
Deployment Models
Managed, sovereign cloud, on-premises or fully air-gapped, with the same capability in each.
Built to the standards that matter
Framework names denote the standards S32’s controls are built to and assessed against. They are not claims of third-party certification except where explicitly stated. Contact our team for current attestation letters and scope.
Compliance posture, in detail
- GDPREU data protection, with a 30-day deletion pipeline
- CCPA / CPRACalifornia privacy, global suppression
- Privacy ActGovernment records-privacy alignment
- HIPAASafeguards for regulated health data
- FERPAEducation-records privacy alignment
- SOC 2 Type IIIn progressAttestation underway — security, availability, confidentiality
- NIST 800-53Security-controls alignment
- COBITIT-governance alignment
- PCI DSSCardholder data isolated with certified processors
- ISO 27001On roadmapInformation-security management
- CALEALawful-interception compliance by design
- CJISCriminal-justice information security
- CMMCDefense-industrial base controls
- FedRAMP ModerateOn roadmapU.S. federal cloud authorization
- Five Eyes eligibilityVetted-partner provisioning
Posture reflects S32’s current state and is updated as milestones are met.
Built-in commitments
Provenance on every claim
Data carries how it got there — raw, derived, enriched, or corroborated — so findings are traceable and defensible.
Append-only audit
Every consequential mutation lands in an immutable audit log: who, what, when, and the exact change.
Least privilege by default
Workspaces are isolated, access runs least-privilege, and sensitivity ceilings gate what each user can see and do.
Policy-gated actions
Consequential operations pass a deterministic policy decision before they commit — no exceptions, no back doors.
Human in the loop
AI proposes; people decide. No autonomous high-impact actions, with hard spend rails and a kill switch on every agent.
Data sovereignty
Deploy managed, on-premise, or air-gapped. Your data stays queryable, exportable, and owned — no vendor lock-in.
How we operate — and what we won’t do
How we operate
- Capabilities are provisioned only to vetted, eligible buyers — government, defense, law enforcement, service providers, and critical-infrastructure operators.
- Lawful-access capabilities operate only under proper legal authority, and every access is logged against that authority.
- Consequential actions keep a human in the loop — proposals are reviewed and approved before they execute.
- Deployments respect data sovereignty: managed, on-premise, or air-gapped, with the customer owning the data.
What we won’t do
- No sale or provisioning to unvetted parties, regardless of deal size.
- No operation of interception or collection capabilities outside a lawful mandate.
- No autonomous high-impact actions — AI never suspends, deletes, or publishes without human approval.
- No silent data sharing: customer data is never used to train models or shared across tenants.
Security artifacts
Audit reports & attestations
SOC 2 reports, penetration-test summaries, and attestation letters are available to customers and active evaluators under NDA. Contact our team to request access.