How Incident Index handles your data
Incident Index is committed to security with SOC 2 Type II alignment and ISO 27001-aligned controls.
- Hosted on Amazon Web Services in the United States. Customer records stored in MongoDB.
- TLS in transit. Integration secrets encrypted at rest. Document bodies rely on provider-managed disk encryption.
- Incident Index does not train its own models on your incident data.
- AI processing uses server-managed OpenAI, Anthropic, or Google Gemini APIs. We do not currently set extra zero-retention flags.
- Incident Index is not currently SOC 2 certified. Our security practices are aligned with SOC 2 Type II.
- Incident Index is not currently ISO/IEC 27001 certified. Our controls are aligned with ISO/IEC 27001.
- Enterprise SAML and SCIM are not available yet. There is no customer-facing audit log product today.
- A DPA and SLA are available for Enterprise customers.