Full security page
Enterprise security summary, subprocessors, compliance status, and NDA package request.
Highlights
- Permissions inherited from source systems; Surfaice does not expand entitlements — see Permissions
- Per-user mailbox connections — no tenant-wide mailbox read
- Isolated customer environments on Google Cloud (US regions)
- No customer data used to train models (contractual)
- Audit trail of agent requests — who asked, what tools ran, what was produced
- SOC 2 Type II — in progress via Vanta (observation period ahead of independent audit), expected Q3/Q4 2026; see surfaice.pro/security
In-product trust docs
These pages complement the marketing security summary:- Trust FAQ — procurement and compliance questions
- Audit trail — what is logged and who can access it
- Agent limitations — honest limits on memory, corpus coverage, and accuracy
- Data handling — persistence model and subprocessors