Security & Compliance

Security & Trust

Enterprise-grade security, transparency, and compliance — built in from day one.

View DPA ← staffinity.io
AES-256
Encryption at rest
TLS 1.3
Encryption in transit
Per-Client
Data isolation
AWS ECS
Enterprise infrastructure
SOC 2
In observation period

Compliance & Certifications

Our current compliance posture and certifications in place.

CSA STAR Level 1 — Staffinity
CSA STAR — Level 1 Registered
CSA STAR for AI Level 1 — Staffinity
CSA STAR for AI — Level 1 Registered
SOC 2 Type II In Progress

We are currently in our SOC 2 observation period. Type I audit is targeted for Q3 2026, with Type II certification planned for Q1 2027. Our controls are monitored continuously via automated compliance tooling.

GDPR Compliant Compliant

Staffinity processes data in accordance with GDPR requirements. Our public DPA covers all clients. EU–US transfers use Standard Contractual Clauses (2021 SCCs).

View DPA →
CCPA / CPRA Compliant Compliant

Staffinity complies with California Consumer Privacy Act requirements. We do not sell or share personal information. California residents may submit data requests to privacy@staffinity.io.

Your CA Rights
HIPAA-Ready Architecture Available on Request

Staffinity offers a HIPAA-ready deployment option for healthcare clients, including PHI detection, circuit breaker controls, and Business Associate Agreements (BAAs) for covered entities and business associates.

Request BAA
FINRA-Supportive Architecture Available on Request

Staffinity provides the technical infrastructure broker-dealers need to support their FINRA recordkeeping obligations — including verbatim conversation archiving in WORM-compliant storage meeting SEC Rule 17a-4(f), per-interaction HMAC integrity sealing, 6-year COMPLIANCE-mode retention, and alignment with FINRA Regulatory Notice 24-09 AI guidance. Activated via a signed FINRA Client Addendum.

Request FINRA Addendum
Anthropic Zero Trust for AI Agents Foundation Compliant

Staffinity is among the first agentic AI vendors to achieve compliance with Anthropic's Zero Trust for AI Agents Foundation guideline — and has built architecture that exceeds Foundation requirements across all four pillars.

View How We Comply →

Enterprise AWS Infrastructure

Built on AWS with enterprise-grade controls at every layer.

Primary Region
us-east-2 (Ohio) — data residency in the United States
Encryption
AES-256 at rest via AWS KMS · TLS 1.3 in transit
Logging & Detection
AWS CloudTrail audit logs · GuardDuty threat detection
Availability
Multi-task ECS Fargate · automated failover & health checks
Backups
3-tier retention: daily, weekly, and monthly snapshots
Vulnerability Scanning
ECR container image scanning on every build pipeline run

Anthropic Zero Trust for AI Agents — Foundation Compliant

How Staffinity meets and exceeds each Foundation-level requirement.

Reference Document
Zero Trust for AI Agents
Anthropic · May 2026 · 36-page technical framework covering Foundation, Advanced, and Optimized tiers
Read the Anthropic Framework →
Foundation ✓ Compliant Staffinity exceeds Foundation on all requirements
Exceeds
Unique Cryptographic Agent Identity
Foundation requirement: Each agent must have a unique, verifiable identity for every action — not shared credentials or static API keys.
Staffinity uses SigV4 cryptographic workload identity for all orchestrator-to-agent calls. Each request is signed with time-bound AWS STS credentials scoped to the specific agent. Credentials rotate automatically and are never long-lived or shared across clients.
Exceeds
Least-Privilege Access — Scoped Per Task
Foundation requirement: Agents receive only the permissions needed for their specific role — no standing access, no over-provisioned credentials.
Access is enforced at the orchestration layer via Microsoft Entra ID RBAC with per-user data scoping configured in SSM. Agents have zero standing permissions — access is granted per session and scoped to the authenticated user's role. Per-client AWS account isolation means no agent can reach another client's resources at any layer of the stack.
Exceeds
Complete Audit Logging of All Agent Actions
Foundation requirement: Every agent action must be logged in a tamper-evident, auditable record — "what was done" must always be traceable.
Every agent interaction is archived in WORM-compliant S3 Object Lock storage with COMPLIANCE mode and 6-year retention. Each record is sealed with a per-interaction HMAC for tamper detection. This meets SEC Rule 17a-4(f) requirements — a higher bar than the Foundation guideline requires.
Exceeds
Containment & Sandboxing
Foundation requirement: Agents must be isolated from systems they don't need access to — prevent lateral movement and limit blast radius.
Exec sandboxing restricts agent tool use at the runtime layer. An output scanner inspects every agent response for prompt injection, data exfiltration, and policy violations before delivery. PII is detected and redacted before being written to storage. Each client's agent runs in its own dedicated AWS account — complete infrastructure isolation, not just logical separation.

AWS Well-Architected Framework Review

Our infrastructure has been independently reviewed against all six pillars of the AWS Well-Architected Framework. Zero high-risk findings across every pillar.

AWS Well-Architected
AWS Well-Architected Review
Staffinity AI Agent Platform  ·  May 2026
0 High Risk 0 Medium Risk 57 Best Practices Met
View Report Findings
Operational Excellence
11 / 11 best practices met · zero risks
Security
11 / 11 best practices met · zero risks
Reliability
13 / 13 best practices met · zero risks
Performance Efficiency
5 / 5 best practices met · zero risks
Cost Optimization
11 / 11 best practices met · zero risks
Sustainability
6 / 6 best practices met · zero risks

Per-Client Data Isolation

Every Staffinity client runs in dedicated infrastructure — separate ECS clusters, isolated databases, and client-specific encryption keys. Your data is never co-mingled with another client's data, at any layer of the stack.


G7 France Évian 2026

Guidance jointly published by G7 Cybersecurity Working Group · France 2026 Presidency

Software Bill of Materials for AI (SBOM for AI)

Transparency and traceability across Staffinity's AI supply chain — aligned with G7 minimum elements guidance.

G7 SBOM for AI Aligned

Staffinity's SBOM for AI is prepared in accordance with the G7 Cybersecurity Working Group's SBOM for AI Minimum Elements guidance (2026), jointly published by CISA, NCSC, BSI, ANSSI, ACN, CSE, NCO, and the EU Commission. We are among the first AI agent vendors to publish a machine-readable SBOM for AI.

Download SBOM (CycloneDX JSON)
Supply Chain Transparency

Our SBOM for AI documents all 7 G7 clusters: Metadata, System Level Properties, Models (Claude Sonnet 4.6, AWS Titan Embed V2), Datasets, Infrastructure (dedicated per-client AWS accounts), Security Properties (Entra ID RBAC, KMS encryption, WORM audit trail, prompt injection controls), and Key Performance Indicators.

Model Provenance

Staffinity's primary reasoning model is Anthropic® Claude Sonnet 4.6. Client data is never used to train AI models — enforced through Anthropic's Enterprise DPA and GLBA addendum. Model weights for hosted API models are proprietary to their respective vendors, consistent with G7 guidance limitations for third-party models.

Security Properties

Every agent deployment includes: AES-256 KMS encryption (per-client CMK), TLS 1.3 in transit, Entra ID role-based access control, per-user rate limiting, prompt injection content boundaries, PII detection, and a full interaction audit trail in WORM-compliant storage.

Note on model hash values: Hash values for model weights are not available for hosted API models (Anthropic Claude, AWS Titan Embed) as the weights are proprietary to the respective vendors. This is a known limitation documented in G7 SBOM for AI guidance for third-party hosted models. Staffinity documents this limitation transparently in our published SBOM.


AI Provider Commitments

We are transparent about every AI provider we use and their data handling commitments.

Provider Role Data Commitment Certification
Anthropic
Claude AI
Primary AI model for agent responses and reasoning Data is not used to train shared models. Enterprise data processing agreement in place.
✓ No shared model training
Enterprise DPA
Amazon Web Services
Infrastructure
Cloud infrastructure, storage, compute, and networking Data processed under AWS standard DPA. Covered under AWS Enterprise Agreement.
✓ SOC 2 Type II Certified
SOC 2 Type II
Microsoft Azure
Teams / Identity
Teams platform integration and Azure AD identity management Data processed under Microsoft Enterprise Agreement and DPA.
✓ ISO 27001 Certified
ISO 27001
Perplexity AI
Web Search
Web search capability for agents requiring real-time information Used for search queries only. No conversation content or personal data is transmitted to Perplexity.
✓ No conversation data shared
Limited Scope

Compliance Framework Alignments

Independently documented alignment with key regulatory and industry frameworks. All reports publicly available.

NIST AI RMF Aligned

Staffinity maps to all four functions of the NIST AI Risk Management Framework 1.0 — Govern, Map, Measure, and Manage — across 27 documented controls.

View Report →
FINRA Aligned Documented

Staffinity supports FINRA member firm clients with platform controls aligned to Rule 4370 (BCP), Regulatory Notice 24-09 (AI), Rule 3110 (Supervision), and SEC Rule 17a-4 (Records).

View Report →
EU AI Act Limited Risk

Formal risk classification confirms Staffinity agents are Limited Risk under Regulation (EU) 2024/1689. All Article 50 transparency obligations met. Not classified as High Risk.

View Report →

Our Compliance Roadmap

A transparent view of where we are and where we're going.

HIPAA-Ready Architecture
April 2026 · PHI detection, circuit breaker controls, BAA-ready
GDPR Compliant
May 2026 · SCCs in place, DPAs available for all clients
CCPA / CPRA Compliant
May 2026 · No data sale, California privacy rights honored
SOC 2 Type I In Progress
Q3 2026 · Observation period active, controls monitored
SOC 2 Type II Planned
Q1 2027 · Full audit with Type I as foundation
ISO 27001
2027 · Information security management certification
ISO 42001 — AI Management
2027 · AI governance and responsible AI management certification

Security Questions?

We're transparent. Reach out any time.

Security Questions

security@staffinity.io

Privacy Requests

privacy@staffinity.io

Request DPA / BAA

privacy@staffinity.io