Encryption
Production data is encrypted in transit and at rest using controls provided by Darwin and its production infrastructure.
Security / Current posture
Darwin applies layered technical and operational safeguards to protect customer information. This page describes the posture we have today without claiming certifications we have not earned.
Control model
Production data is encrypted in transit and at rest using controls provided by Darwin and its production infrastructure.
Tenant-aware application controls and database row-level security restrict customer data access.
Microsoft Entra identity, role-based authorization, least privilege, and action logging protect operational access.
Production services run on managed AWS infrastructure with documented network, backup, access, and deployment controls.
Documented escalation, notification, containment, recovery, and evidence-preservation procedures govern security events.
Providers are inventoried and reviewed according to the sensitivity and operational importance of the data they process.
Compliance readiness
Darwin maintains a documented SOC 2 readiness program. Darwin is not currently SOC 2 certified and has not begun an observation window. We document which infrastructure controls are inherited from providers and which remain Darwin’s responsibility.
Qualified customers may request current architecture, control, vendor, and risk information during diligence.
Security contact
Contact security@darwin-tech.ai. Customer-specific commitments are governed by the applicable written agreement.