Skip to content

Trust

Security and governance

Phoeniks treats security controls as engineered platform capabilities rather than policy statements: role-based access, tenant isolation, immutable audit logging over data access and model runs, encryption in transit and at rest, and regional residency options.

What this document commits to

Access model
Role-based, tenant isolated
Audit logging
Immutable over access, exports, model runs
Residency options
EU, Brazil, Thailand, India
Data-subject tooling
Shared across GDPR, LGPD, PDPA, DPDP
01

Controls#

  • Role-based access control with tenant isolation between institutional clients.
  • Immutable audit logging over data access, exports and model runs.
  • Encryption in transit and at rest, with separated key management.
  • Regional data residency options for EU, Brazilian, Thai and Indian data.
  • Documented change management over model and pipeline releases.
  • Incident response with defined notification paths.
02

Data-subject rights#

Access, rectification and erasure requests are handled through platform tooling shared across GDPR, LGPD, PDPA and DPDP obligations, so a request is executed consistently regardless of jurisdiction.

Frequently asked

Is client data used to train models?
No. Client-supplied data is isolated to that client's tenant and is not used to improve models for other clients unless a separate written agreement says otherwise.

Related pages

See also

Request access

Institutional access. No self-serve trial.

Request access