AI Governance and Privacy at Twin1

Your data is yours. Full stop.

Twin1 is built for the most sensitive environments in professional services, financial services, and the enterprise. We didn't bolt on security after the fact. Governance, privacy, and compliance are built into the architecture from day one.

Certifications & Governance

Enterprise-ready from day one.

Certifications

Independently audited and validated through Vanta.

SOC 2 Type II

AICPA SOC 2 — Service Organization Control Reports badge

ISO 27001

ISO 27001 Information Security Management — Certified badge

Google CASA Level 3

Only share what you want

You have complete control.

01Pre-Ingestion Filters
02Inherited Permissions (IAM)
03Contextual Privacy

Information sharing is filtered dynamically by user, role, topic, and peer-to-peer settings.

04Client Exclusion
05Human-in-the-Loop

Your data stays protected

Encryption

All data is protected with enterprise-grade encryption at every layer.

Data in Transit
TLS 1.3 on every connection between client, services, and storage
Data at Rest
AES-256 for all stored customer data, indices, and backups
Key Management
Azure Key Vault — RSA-wrapped keys, hardware-backed.

Your Data Will Never Train an AI Model

This is a contractual commitment, not a policy statement. Customer data is never used to train underlying LLMs without your explicit written consent. Your firm's data remains strictly private and unique to your deployment.

Tenant Isolation
Each tenant has a dedicated, encrypted storage bucket. No data is ever co-mingled at the storage layer.
Index Separation
Each tenant’s data is stored in separate indices within the search service.
Right to Delete
Data deleted by a user is deleted by the Twin. On termination or expiry of a contract, Twin1 deletes all customer data.

Data Residency

Data is hosted with cloud providers in a jurisdiction agreed with each customer. Current available regions include the USA, EU, and Singapore.

Region · NA
US-region storage and processing across SaaS, Hybrid, and Private Cloud deployments.
Region · EU
EU-region storage and processing. GDPR-aligned by default. Frankfurt & Amsterdam zones.
Region · SGP
SGP-region storage and processing. MAS-aligned for regulated firms.
Region · AUS
AUS-region storage and processing across SaaS, Hybrid, and Private Cloud deployments.

Security is not a snapshot

— it is a continuous programme.

Policy & Governance Reviews

Security and data protection policies are reviewed regularly and updated alongside major business changes.

Independent Security Testing

Independent penetration testing and adversarial exercises continuously evaluate the resilience of the platform, including prompt injection scenarios.

Certified Security Audits

SOC 2 Type II and ISO 27001 audits independently validate Twin1's security controls and governance practices.

Continuous Monitoring

Infrastructure, source code, and dependencies are continuously monitored through automated vulnerability scanning and intrusion detection systems.

Audit & Incident Traceability

Full audit trails are maintained for all user activity and are accessible through the admin interface for internal review.

Vulnerability Disclosure

A formal disclosure programme supports the responsible reporting and remediation of potential security vulnerabilities.

Flexible deployment options to meet your infrastructure and data sovereignty requirements.

Full SaaS

Data stored in secured Twin1 GCP/Azure servers, subject to full security requirements including encryption at rest and in transit.

Single Tenant

Data stored and processed in a dedicated Twin1 server on GCP/Azure.

Private Cloud

Data and Twin1 processing both run entirely within your own private cloud environment.

Book a demo

See Twin in action. Drop your email in below and book a call with us.