Security / Current posture

Trust requires controls—and precise claims.

Darwin applies layered technical and operational safeguards to protect customer information. This page describes the posture we have today without claiming certifications we have not earned.

Control model

Protection across identity, data, infrastructure, and operations.

01

Encryption

Production data is encrypted in transit and at rest using controls provided by Darwin and its production infrastructure.

02

Tenant isolation

Tenant-aware application controls and database row-level security restrict customer data access.

03

Identity and access

Microsoft Entra identity, role-based authorization, least privilege, and action logging protect operational access.

04

Infrastructure

Production services run on managed AWS infrastructure with documented network, backup, access, and deployment controls.

05

Incident response

Documented escalation, notification, containment, recovery, and evidence-preservation procedures govern security events.

06

Vendor governance

Providers are inventoried and reviewed according to the sensitivity and operational importance of the data they process.

Compliance readiness

Current status, stated plainly.

Darwin maintains a documented SOC 2 readiness program. Darwin is not currently SOC 2 certified and has not begun an observation window. We document which infrastructure controls are inherited from providers and which remain Darwin’s responsibility.

Qualified customers may request current architecture, control, vendor, and risk information during diligence.

SECURITY PROGRAM ACTIVE · CERTIFICATION NOT CLAIMED

Security contact

Questions or vulnerability reports.

Contact security@darwin-tech.ai. Customer-specific commitments are governed by the applicable written agreement.

Need security information for a current evaluation?

Contact security