Compliance & Security

Define the controls for your work. Review the evidence together.

Agree where data is stored, which services receive it, who can act and which decisions need a record. Review the deployment, model provider and security requirements for your selected workflow before access is granted.

Assurance documentation

Review the applicable evidence with your security team before approving the engagement.

SOC 2 assurance

Review the applicable evidence

Request the current assurance documentation and review the audited entity, system scope, report period and exceptions with your security team. A public summary does not replace that review.

ISO 27001 assurance

Review the applicable evidence

Request the applicable certificate and scope for review. Confirm which entity, services and locations it covers before treating it as evidence for your engagement.

Define your deployment requirements

Confirm the supported configuration and controls for your selected environment.

Storage and deployment

Agree the hosting location, tenant isolation, data residency and access required for the environment. Confirm the supported cloud or on-premises deployment before committing to a topology.

Identity and permitted actions

Define learner, administrator and operating-owner access. Review the SSO, role mapping and permission controls supported by the selected environment, including what an agent may do without human approval.

Encryption and key ownership

Review encryption in transit and at rest, key ownership and any customer-managed key requirement. Record the applicable configuration and evidence in the engagement's security review.

Model-provider data flow

When an external model API is used, the request data is sent to that provider over an encrypted connection. Review its retention terms and account settings. An approved model hosted inside your network can keep inference there; review other connected services separately.

Configurable per engagement

Agree the scope during your InfoSec walkthrough and record the commitments in the applicable agreement and security response.

Audit evidence and retention

Agree which prompts, outputs, tool actions, human decisions and administrative events must be recorded. Confirm available logging, retention, access and export mechanisms for the selected environment; do not assume every action is captured automatically.

Practice-environment controls

Agree permitted data, clipboard and file-transfer policies, credentials and connected services. Confirm which restrictions the selected lab and customer endpoint can enforce before practice begins.

Providers and data handling

Review the services that process engagement data, including hosting, identity and model providers. Confirm the applicable data-processing terms, disclosure and any onward transfer with your security and legal owners.

Assurance and security review

Bring your security questionnaire and required evidence. Agree the documentation, test reports and contractual controls needed for the selected scope. Certification and legal compliance must be assessed against the actual service and deployment.

Agree the requirements before use

Your security and legal owners review the requirements, supporting evidence and commitments.

Required data protection and industry-specific controlsReview with your owners
Hosting, model provider and network boundaryConfirm the configuration
Logs, retention, export and deletion requirementsAgree in scope

Frequently Asked Questions

Agree the supported hosting location and region for the engagement. Storage location and model processing are separate questions: an external model API may receive request data even when the application is hosted in your cloud. Review both paths before sharing data.
Specify the policy for the selected lab, customer endpoint and connected tools. Confirm which clipboard, upload, download and recording controls are supported and how they will be tested. These restrictions are not assumed to apply to every environment.
An external model API receives the data included in a request over an encrypted connection. Retention and zero-retention eligibility depend on the provider, service, account settings and contract. Inference on a model hosted inside your network can remain there; other integrations may still transmit data and must be reviewed separately.
Agree the events, retention period, access and export format required for the workflow. Confirm the logging mechanisms available in the chosen environment. Human assessment evidence, agent behavior evidence and production audit records have different purposes and should be reviewed separately.
Request the applicable assurance documentation through the security review. Your security team should verify the entity, scope, validity or report period and any exceptions against the service you plan to use.
Bring the requirements that apply to your organization and intended use. Your security and legal owners review the data flows, processing terms, retention, deletion and access controls for the engagement. A platform feature or assurance report does not itself establish compliance with every applicable requirement.
Review the applicable hosting, identity, model and other connected services for the selected configuration. Confirm their roles, data access and contractual terms before the environment is approved.
Request the applicable test documentation and review its scope, date, findings and remediation status with your security team. Agree any further testing or remediation requirements before use.
Define the retention and deletion requirements for application data, assessment records, logs, backups and provider-held data. Confirm the supported process and contractual commitments for each before the engagement begins.

Need to send your InfoSec questionnaire?

Bring the questionnaire, data-flow requirements and assurance evidence your security team needs. Confirm the applicable scope and supporting documentation in a walkthrough.

Discuss Security Requirements