Subconscious.ai / Legal
Security at Subconscious.ai
Last updated August 25, 2026
Subconscious maintains a SOC 2 Type I report through Vanta. The current report and supporting security documentation are available under NDA.
This page states the controls and data-handling commitments we can support now. Customer and partner agreements may incorporate it by reference.
Assurance
Our SOC 2 Type I report evaluates the design of controls at a point in time. We maintain written information security, access control, incident response, data management, secure development, third-party management, and continuity policies.
Enterprise customers may request the current report and applicable security documentation under NDA at security@subconscious.ai.
Access and encryption
Administrative access uses unique accounts, multi-factor authentication, and least-privilege controls. Data is protected in transit and at rest using the security capabilities of our managed infrastructure providers. Secrets are kept outside source control and production access is restricted to authorized personnel.
Data separation
Customer and partner data is logically separated. Production is separated from development and test. We do not use production data in non-production environments unless it has been de-identified or the applicable agreement permits it.
Model development
Customer and partner data used for model development is processed in our controlled environment or by an approved subprocessor. We do not submit it to consumer or free-tier AI services. Foundation model providers are engaged under terms that prohibit training on data we submit.
Our models do not store source data in retrievable form. Deletion removes source data from active systems under the applicable agreement and excludes it from later training runs. It does not require retraining an existing model.
Incidents
We maintain an incident response process. Confirmed incidents affecting customer or partner data are handled and communicated under the applicable agreement and data processing addendum.
Subprocessors
Our subprocessor page describes how to obtain the current register and how contract notifications work.
Report a vulnerability
Email security@subconscious.ai with a description, reproduction steps, and contact details. Good-faith research must not access or modify other people's data, degrade the service, or disclose a finding before we have had reasonable time to investigate and address it.