AI Governance and Privacy at Twin1
Twin1 is built for the most sensitive environments in professional services, financial services, and the enterprise. We didn't bolt on security after the fact. Governance, privacy, and compliance are built into the architecture from day one.
Certifications & Governance
Enterprise-ready from day one.
Certifications
Independently audited and validated through Vanta.
SOC 2 Type II

ISO 27001

Google CASA Level 3
Only share what you want
You have complete control.
Information sharing is filtered dynamically by user, role, topic, and peer-to-peer settings.
Your data stays protected
Encryption
All data is protected with enterprise-grade encryption at every layer.
Your Data Will Never Train an AI Model
This is a contractual commitment, not a policy statement. Customer data is never used to train underlying LLMs without your explicit written consent. Your firm's data remains strictly private and unique to your deployment.
Data Residency
Data is hosted with cloud providers in a jurisdiction agreed with each customer. Current available regions include the USA, EU, and Singapore.
Security is not a snapshot
— it is a continuous programme.
Policy & Governance Reviews
Security and data protection policies are reviewed regularly and updated alongside major business changes.
Independent Security Testing
Independent penetration testing and adversarial exercises continuously evaluate the resilience of the platform, including prompt injection scenarios.
Certified Security Audits
SOC 2 Type II and ISO 27001 audits independently validate Twin1's security controls and governance practices.
Continuous Monitoring
Infrastructure, source code, and dependencies are continuously monitored through automated vulnerability scanning and intrusion detection systems.
Audit & Incident Traceability
Full audit trails are maintained for all user activity and are accessible through the admin interface for internal review.
Vulnerability Disclosure
A formal disclosure programme supports the responsible reporting and remediation of potential security vulnerabilities.
Flexible deployment options to meet your infrastructure and data sovereignty requirements.
Full SaaS
Data stored in secured Twin1 GCP/Azure servers, subject to full security requirements including encryption at rest and in transit.
Single Tenant
Data stored and processed in a dedicated Twin1 server on GCP/Azure.
Private Cloud
Data and Twin1 processing both run entirely within your own private cloud environment.
Book a demo
See Twin in action. Drop your email in below and book a call with us.
