Security at IGS
Last updated: July 1, 2026
Security is foundational to everything we build at IGS. Our platform is designed for enterprises that handle sensitive financial data, protected health information, and proprietary business content. We employ a defense-in-depth strategy across people, processes, and technology.
1. Encryption
1.1 Data at Rest
All customer data is encrypted at rest using AES-256 encryption. Database volumes, backups, and file storage are all encrypted. Encryption keys are managed through a hardware security module (HSM) with automatic rotation.
1.2 Data in Transit
All network communication is encrypted using TLS 1.3. API endpoints enforce strong cipher suites and certificate pinning. Internal service-to-service communication is also encrypted.
1.3 On-Premise Deployments
For on-premise deployments, all data remains within your infrastructure. No telemetry, logs, or model data leave your environment unless explicitly configured. Encryption keys are managed by your team.
2. Access Control
- Role-Based Access Control (RBAC): Granular permissions per user, role, and resource.
- Multi-Factor Authentication (MFA): Required for all administrative access.
- Just-in-Time Access: Engineers have zero standing access to production systems. Access is granted via approved, time-bound requests with full audit trails.
- Principle of Least Privilege: All access is scoped to the minimum necessary.
3. Infrastructure Security
- Network Segmentation: Production, staging, and development environments are fully isolated.
- Web Application Firewall (WAF): Protects against OWASP Top 10 threats.
- DDoS Protection: Multi-layer DDoS mitigation at network and application levels.
- Intrusion Detection: 24/7 monitoring with automated threat response.
- Hardened Base Images: All servers run from CIS-benchmarked, minimal images.
4. Vulnerability Management
- Continuous Scanning: Automated vulnerability scanning of all infrastructure and dependencies.
- Penetration Testing: Third-party penetration tests conducted quarterly.
- Bug Bounty Program: We welcome responsible disclosure. Contact igs@neuriva.ai.
- Patch Management: Critical patches applied within 24 hours. Standard patches within 7 days.
5. Compliance and Certifications
5.1 SOC 2 Type II
IGS undergoes annual SOC 2 Type II audits covering security, availability, and confidentiality. Our most recent audit is available upon request under NDA.
5.2 HIPAA
We execute Business Associate Agreements (BAAs) with healthcare customers. Our platform meets the administrative, physical, and technical safeguards required by HIPAA.
5.3 GDPR
We support Data Processing Agreements (DPAs), Data Protection Impact Assessments (DPIAs), and data subject rights requests. Data is processed in accordance with GDPR standards.
5.4 AI-Specific Safeguards
- Model Isolation: Customer AI agents are deployed in isolated environments. No cross-tenant data leakage.
- Data Governance: Customers control what data is used for model training, inference, and logging.
- Audit Trails: Every model input, output, and configuration change is logged immutably.
- Bias Monitoring: Automated fairness and bias checks on model outputs.
6. Data Backup and Disaster Recovery
- Automated Backups: Full backups every 6 hours with point-in-time recovery.
- Geographic Redundancy: Data replicated across multiple availability zones.
- RPO: 1 hour. RTO: 4 hours.
- Disaster Recovery Tests: Full DR exercises conducted quarterly.
7. Employee Security
- Background Checks: All employees undergo background screening.
- Security Training: Mandatory quarterly security awareness training.
- Code Review: All code changes require peer review and automated security scanning.
- Zero Standing Privileges: No employee has permanent production access.
8. Vendor and Third-Party Risk
We assess all third-party vendors against our security requirements. Critical vendors undergo quarterly reviews. We maintain an inventory of all sub-processors available to customers on request.
9. Incident Response
Our incident response process follows the NIST framework:
- Preparation: Documented runbooks, on-call rotations, and war room protocols.
- Detection: Automated alerting from SIEM, IDS, and application monitoring.
- Containment: Immediate isolation of affected systems.
- Eradication: Root cause analysis and remediation.
- Recovery: Verified restoration from clean backups.
- Post-Mortem: Full incident report with improvements.
Customers are notified within 24 hours of any confirmed security incident affecting their data.
10. Report a Vulnerability
If you discover a security vulnerability, please contact us immediately:
Email: igs@neuriva.ai
Phone: +20 110 879 8713
WhatsApp: +20 110 879 8713
We commit to acknowledging receipt within 24 hours and providing regular updates on remediation progress. We appreciate responsible disclosure and will acknowledge your contribution.
11. Contact Our Security Team
For security-related inquiries, compliance questions, or to request our SOC 2 report, contact:
Email: igs@neuriva.ai
Phone: +20 110 879 8713