Security at IGS

Last updated: July 1, 2026

Security is foundational to everything we build at IGS. Our platform is designed for enterprises that handle sensitive financial data, protected health information, and proprietary business content. We employ a defense-in-depth strategy across people, processes, and technology.

SOC 2 Type II HIPAA Compliant GDPR Compliant AES-256 Encryption ISO 27001 aligned

1. Encryption

1.1 Data at Rest

All customer data is encrypted at rest using AES-256 encryption. Database volumes, backups, and file storage are all encrypted. Encryption keys are managed through a hardware security module (HSM) with automatic rotation.

1.2 Data in Transit

All network communication is encrypted using TLS 1.3. API endpoints enforce strong cipher suites and certificate pinning. Internal service-to-service communication is also encrypted.

1.3 On-Premise Deployments

For on-premise deployments, all data remains within your infrastructure. No telemetry, logs, or model data leave your environment unless explicitly configured. Encryption keys are managed by your team.

2. Access Control

3. Infrastructure Security

4. Vulnerability Management

5. Compliance and Certifications

5.1 SOC 2 Type II

IGS undergoes annual SOC 2 Type II audits covering security, availability, and confidentiality. Our most recent audit is available upon request under NDA.

5.2 HIPAA

We execute Business Associate Agreements (BAAs) with healthcare customers. Our platform meets the administrative, physical, and technical safeguards required by HIPAA.

5.3 GDPR

We support Data Processing Agreements (DPAs), Data Protection Impact Assessments (DPIAs), and data subject rights requests. Data is processed in accordance with GDPR standards.

5.4 AI-Specific Safeguards

6. Data Backup and Disaster Recovery

7. Employee Security

  • Background Checks: All employees undergo background screening.
  • Security Training: Mandatory quarterly security awareness training.
  • Code Review: All code changes require peer review and automated security scanning.
  • Zero Standing Privileges: No employee has permanent production access.

8. Vendor and Third-Party Risk

We assess all third-party vendors against our security requirements. Critical vendors undergo quarterly reviews. We maintain an inventory of all sub-processors available to customers on request.

9. Incident Response

Our incident response process follows the NIST framework:

  • Preparation: Documented runbooks, on-call rotations, and war room protocols.
  • Detection: Automated alerting from SIEM, IDS, and application monitoring.
  • Containment: Immediate isolation of affected systems.
  • Eradication: Root cause analysis and remediation.
  • Recovery: Verified restoration from clean backups.
  • Post-Mortem: Full incident report with improvements.

Customers are notified within 24 hours of any confirmed security incident affecting their data.

10. Report a Vulnerability

If you discover a security vulnerability, please contact us immediately:

Email: igs@neuriva.ai
Phone: +20 110 879 8713
WhatsApp: +20 110 879 8713

We commit to acknowledging receipt within 24 hours and providing regular updates on remediation progress. We appreciate responsible disclosure and will acknowledge your contribution.

11. Contact Our Security Team

For security-related inquiries, compliance questions, or to request our SOC 2 report, contact:

Email: igs@neuriva.ai
Phone: +20 110 879 8713