Wolfia Trust Center

We help sales, security, and support teams get answers in seconds without depending on subject-matter experts. Our AI agent connects to every source that already holds the truth (Google Drive, Notion, Slack, email, website, trust center, SOC 2 docs, etc.). It keeps that knowledge graph fresh on its own and drafts, validates, and formats responses to customer questions, security questionnaires, and RFPs, all in the background, so your team just reviews and ships.

Powered by Wolfia. Review compliance certifications, security policies, subprocessors, and request access to detailed documentation.

Skip to main content
Wolfia Trust Center

Wolfia Trust Center

We help sales, security, and support teams get answers in seconds without depending on subject-matter experts.

Our AI agent connects to every source that already holds the truth (Google Drive, Notion, Slack, email, website, trust center, SOC 2 docs, etc.). It keeps that knowledge graph fresh on its own and drafts, validates, and formats responses to customer questions, security questionnaires, and RFPs, all in the background, so your team just reviews and ships.

security@wolfia.com

Access control

Robust identity and permission safeguards prevent unauthorized system access and enforce least-privilege principles

Single sign-on support

Customers can enforce their own identity policies through SAML 2.0 and OpenID Connect, allowing corporate MFA, conditional access, and streamlined user lifecycle management.

Automated user provisioning

Directory sync lets customers provision, update, and deprovision their users automatically from their identity provider.

Role-based access control

Role-based access control maps permissions to job function so each user receives only the access they need.

Formal onboarding and off-boarding

New users receive documented approval before accounts are created and departing users have all access disabled within one business day, eliminating orphaned credentials.

Encrypted administrative access

Production environments may only be reached through approved encrypted channels, safeguarding credentials and session data in transit.

Annual access reviews

Documented reviews of all production accounts verify that privileges remain appropriate and any unnecessary access is removed.

Multi-factor authentication

Employee access to internal systems requires single sign-on with enforced multi-factor authentication, and customers can require their own identity provider for their users.

Data security

Encryption, retention and classification controls protect customer information throughout its lifecycle

Encryption at rest

Customer data, temporary files and backups are protected with strong AES-256 encryption whenever stored on disk.

Encryption in transit

Secure transport protocols are mandated for all external and internal transfers, preventing eavesdropping over public networks.

Data retention and deletion policy

Customer data, including encrypted backups, is purged within 90 days of contract termination or a verified deletion request, as committed in the Data Processing Agreement.

Full-disk workstation encryption

Company-issued laptops are required to use whole-disk encryption, preventing data loss if a device is lost or stolen.

Data classification scheme

Information is labeled as secret, confidential, internal, or public, enabling appropriate handling, retention, and disposal according to sensitivity.

Application security

A mature secure development lifecycle and continuous testing keep the platform resilient against software threats

Secure development policy

Documented standards embed security requirements throughout design, coding, testing, and deployment activities.

Static code analysis

Static code analysis runs automatically on every change before it can be merged.

Dependency and image vulnerability scanning

Dependencies and container images are automatically scanned for known vulnerabilities on every change, and patches are applied promptly.

Annual third-party penetration testing

Independent security experts test the web application and API at least annually. The most recent test closed with zero open findings after remediation, and the report is available under NDA.

Web application firewall

A managed WAF blocks common web threats and combined DDoS protection keeps the service available even during volumetric attacks.

Secret scanning and rotation

Secret scanning runs on every commit, and any exposed credential is rotated promptly.

Trusted container images

All application containers are built from approved sources and stored in a private registry to block malicious code insertion.

Deployment approval workflow

Changes reach production only through pull requests to a protected branch that must pass automated security and quality checks before they can be merged.

Infrastructure security

Layered cloud defenses harden the hosting environment against network and platform attacks

Automated scaling and load balancing

The platform automatically provisions resources and distributes traffic as usage grows, maintaining performance without manual intervention.

Encrypted backups with geographic redundancy

Encrypted backups run daily with continuous point-in-time recovery and are copied to a second geographic region so data can be restored after a regional outage.

Cloud threat detection

Cloud-native threat detection continuously analyzes account, network, and audit activity and alerts the security team.

Multi-zone redundancy

Production runs across multiple availability zones, with backups copied to a second region for disaster recovery.

Private network segmentation

Production systems run in private networks. Only required inbound ports are exposed, and databases and the cluster control plane are not reachable from the internet.

Baseline configuration enforcement

Infrastructure and platform configuration are defined as code, reviewed before deployment, and continuously reconciled against the approved state.

Incident response

Documented processes and regular drills ensure swift detection, containment and communication of security events

Incident response plan

Clear playbooks define roles, escalation paths and customer notification procedures for security events.

Annual incident simulations

Table-top and drill exercises test the plan each year, driving improvements from real-world lessons.

Real-time security alerting

Monitoring tools send immediate notifications to dedicated channels, ensuring swift human review of potential incidents.

Ticket-based incident tracking

All incidents are logged and tracked to closure, providing auditable evidence of timely remediation.

Evidence preservation procedures

All incident workflows include collecting and safeguarding logs and artifacts to support forensic analysis and reporting.

Root-cause analysis reviews

Post-incident reviews identify systemic issues and feed improvements back into the security program.

Dedicated incident response team

Trained personnel are on call to triage, contain, and communicate security incidents, ensuring rapid, coordinated action.

Compliance and auditing

Independent attestations, internal reviews and insurance demonstrate commitment to recognized frameworks

SOC 2 Type II report

A licensed CPA firm verified that controls for security, availability, and confidentiality were designed and operated effectively throughout the audit period.

Annual control self-assessments

Management reviews each security control yearly to verify effectiveness and document remediation actions.

Compliance management platform

A compliance management platform tracks control ownership and evidence collection for the SOC 2 program.

Annual policy review and approval

Senior management formally re-evaluates and signs off on the information security program every year to keep it current.

Coordinated vulnerability disclosure

Security researchers can report vulnerabilities to security@wolfia.com under the published disclosure policy, and reports are triaged and remediated by the security team.

Cyber liability insurance

Cyber liability insurance is in place, and the certificate of insurance is available on request.

Monitoring and logging

Comprehensive, immutable telemetry enables rapid threat detection and forensic analysis

Centralized log management

Application and infrastructure logs are centralized and retained per policy for audit and investigation.

Continuous security monitoring

Automated tools analyze logs and metrics for anomalies, sending high-fidelity alerts to security staff.

Infrastructure performance alerting

Threshold-based alerts on availability and latency notify the on-call engineer.

Immutable audit trails

Administrative users cannot modify or delete their own activity logs, ensuring trustworthy evidence for investigations or audits.

Continuous vulnerability scanning

Workloads and container images are continuously scanned for known vulnerabilities and remediated according to risk.

Public status and metrics page

Customers can view real-time uptime, latency and historical incident data for full operational transparency.

Third-party management

Structured vetting and ongoing oversight reduce supply-chain and subprocessor risks

Vendor due-diligence assessments

Cost, functionality, security, privacy and financial health are evaluated before onboarding any critical provider.

Vendor inventory and risk ranking

All subprocessors are cataloged and scored based on data sensitivity and service criticality, guiding review depth and frequency.

Annual vendor reviews

Critical vendors and subprocessors undergo yearly reassessment to confirm they still meet contractual and security requirements.

Security due-diligence reviews

Contracts and SOC reports are annually examined to verify that vendor controls align with company security and privacy requirements.

Contractual confidentiality obligations

Agreements mandate that vendors uphold security, confidentiality, and privacy commitments consistent with customer expectations.

SOC report reviews for cloud host

Management reviews the cloud hosting provider's SOC 2 attestation each year to validate that complementary controls remain effective.

Zero data retention clauses for AI providers

Every AI provider processes customer data under zero-data-retention and no-training terms; none stores, reviews, or trains on customer data.

Subservice organization monitoring

The cloud hosting provider is the audited subservice organization in the SOC 2 Type II report. Other critical providers, including the AI inference providers, are covered by annual reviews of their SOC 2 Type II reports and data-processing terms. Additional providers are being evaluated for inclusion in the next audit period.

Subprocessor transparency list

An up-to-date list of authorized subprocessors is available to customers, supporting informed risk decisions and compliance obligations.

Privacy and data governance

Policies and processes uphold stringent privacy standards and empower customer control over information

High-standard data handling

All customer information is managed at the highest protection tier, avoiding lower-class segregation.

Confidentiality commitments in contracts

Customer agreements and the public trust center clearly state the company’s obligations for protecting private information.

Privacy policy and DPA

Comprehensive documents define roles, responsibilities, and safeguards for personal data processing in line with global regulations.

Customer-directed data deletion

Data is promptly erased upon customer request and automatically purged when contractual retention limits expire.

Data subject access procedure

Verified requests are fulfilled promptly, giving individuals control over their information and demonstrating regulatory compliance.

Data retention and disposal policy

Information is kept only as long as necessary, with secure deletion processes triggered by schedule or customer request.

No AI training on customer data

Customer content is never used to improve generalized models unless a bespoke contract explicitly authorizes it.

Transparent trust center disclosures

Security objectives, commitments and documentation are published so customers can easily verify privacy practices.

United States data residency

All processing, storage, and AI inference run in United States regions. An alternate storage-at-rest location can be arranged on request under an enterprise agreement; AI inference remains in US regions.

Employee security

People-focused safeguards ensure staff act as strong defenders of customer data

Security awareness training

Every employee completes training at hire and annually thereafter to stay current on threats and responsibilities.

Background screening

Interview, reference, and other checks are completed before onboarding to verify trustworthiness relevant to job duties.

Confidentiality agreements

Employees and contractors formally commit to protecting proprietary and customer information.

Standards of conduct acknowledgment

Employees must read and sign the code of ethics and information security program on hire and annually thereafter.

Centrally managed devices

Company devices are centrally managed with enforced disk encryption, screen lock, and automatic updates.

Formal performance accountability

Security responsibilities are embedded in job descriptions and annual reviews, ensuring individual accountability for control adherence.

Business continuity

Proven recovery capabilities minimize downtime and data loss during disruptive events

Documented BC/DR plan

A comprehensive continuity strategy defines procedures, roles and recovery objectives for critical services.

Annual recovery testing

Backup restores and continuity exercises are run at least annually and measured against the 24-hour recovery objective.

Risk mitigation planning

The organization identifies disruption risks and develops mitigations as part of its broader risk management program.

AI governance

Contractual, technical and procedural controls ensure responsible and secure use of artificial intelligence

Zero-retention model providers

Foundational model partners are contractually bound to discard all prompts and outputs after processing and to prohibit human review.

US-only AI processing

Inference workloads run within United States regions, helping customers satisfy strict data-residency or export-control requirements.

Risk management

Structured assessments identify, prioritize, and drive remediation of threats across the organization.

Annual enterprise risk assessment

Management documents threats, impact and mitigation strategies at least once per year to guide control priorities.

Formal risk management program

Documented methodology identifies, scores, and tracks risks, ensuring mitigation strategies receive appropriate resources.

Quarterly security risk reviews

A cross-functional team reassesses emerging risks each quarter to keep the program aligned with a changing landscape.

Fraud risk assessment

Evaluations consider incentives, opportunities, and potential fraud scenarios, embedding anti-fraud measures into the control framework.

Risk-based control selection

New controls are chosen and adapted based on quantified risk ratings, ensuring resources focus on greatest exposures.