LoadingTrust

The trust profile
your CISO can defend.

CIOC is sold to security teams. That means our own security posture is held to the same standard we hold our customers' to. Read-only by default. Strict isolation. No training on your data. SOC 2 Type I in progress.

Posture

How CIOC sits in
your environment.

Two postures — one for pilots, one for production — both designed to satisfy procurement on day one. No agents. No raw data egress. No surprises in the security questionnaire.

Pilot · 30 days

Read-only by default.

  • Access
    Read-only access to the data sources you choose.
  • Footprint
    No agents installed in your environment. No persistent presence.
  • Data flow
    No raw logs, telemetry, or PII leave your perimeter — only enriched findings.
  • Off-ramp
    Walk away on day 30. All your data is exported and deleted on request.
Production · scoped

Least-privilege
by design.

  • Access
    Scoped, least-privilege integration to the categories you approve.
  • Boundaries
    Only enriched, normalized findings cross into CIOC — never raw payloads.
  • Auditability
    Every action is logged and retained for one year. Audit log export on request.
  • Keys & secrets
    Your credentials are encrypted, segregated from app data, rotated on schedule.
The Commitments

Six commitments
that don't bend.

Procurement reviews focus on the questions a vendor is most likely to dodge. These are our answers to those questions, written before they're asked.

◢ Pilot Posture

Read-only by default.

Read-only access only. No agents in your environment. No raw logs leave your perimeter. Validate value over 30 days before any deeper integration.

◢ Production Integration

Scoped & least-privilege.

Production integration is least-privilege by design. Only enriched, normalized findings cross the boundary into CIOC — never raw logs, telemetry, or sensitive payloads.

◢ Isolation

Strictly multi-tenant.

Strict per-customer isolation, enforced at multiple layers. Cross-tenant access is architecturally impossible — every operation is verified against tenant identity before it executes.

◢ Credentials & Secrets

Your keys, hardened.

Your credentials, API keys, and tokens are encrypted, segregated from application data, and rotated on a defined schedule. Customer-managed keys available for enterprise.

◢ AI Data Handling

No training on your data.

CIOC processes only enriched findings and metadata — never raw logs. Our AI providers are contractually bound: your data is never used to train any foundation model, ours or theirs. Aggregated, de-identified usage statistics only.

◢ Infrastructure & Operations

Hardened & audited.

Modern cloud-native infrastructure with defense-in-depth. TLS 1.3 in transit, AES-256 at rest. Daily backups with tested restore. Continuous monitoring with one-year audit log retention. Annual penetration test by an independent firm.

SOC 2 Type ITarget Q4 2026
Cloud-NativeUS-hosted · isolated
TLS 1.3 · AES-256In transit + at rest
72hr Breach NotifyGDPR-aligned
DPA AvailablePre-signed template
Security questionnaire

Need the full packet?

Procurement teams reading questionnaires under NDA get the full security profile — pen-test summary, sub-processor list, DPA, vendor management policy, incident response plan. Email sherry@cioc.io and the packet is on the way the same business day.

Begin a Pilot

Trust earned,
not claimed.

A 30-day pilot with read-only access. Your security review runs in parallel. Walk away or convert on day 30.