Trust & Security

Security at Deflected

We build a security company, so security is not a feature we bolt on — it is the product. This page explains how we protect the data you entrust to us: defense-in-depth, post-quantum encryption by default, strict tenant isolation, and a governance program aligned to the frameworks your auditors care about.

Our security philosophy

Deflected exists to secure the AI layer for other organizations. That mission only holds if our own house is in order, so we hold ourselves to the same standard we ask of our customers: security is the product, not a compliance checkbox.

Three principles shape every decision we make about how data moves through our systems:

We treat security as an engineering discipline with owners, budgets, and measurable outcomes — not as a document reviewed once a year.

Encryption

Encryption at Deflected is post-quantum by default. We do not offer post-quantum protection as a premium tier; it is the baseline for every byte we handle. This matters because of a threat that is already in motion: adversaries can capture encrypted traffic today and store it to decrypt later, once a large quantum computer can break classical public-key cryptography. This is the harvest-now, decrypt-later problem, and it means any data that will still be sensitive years from now needs post-quantum protection today.

We use the algorithms standardized by the U.S. National Institute of Standards and Technology (NIST):

FIPS 203
ML-KEM-1024 key encapsulation
FIPS 204/205
ML-DSA & SLH-DSA signatures
Hybrid
X25519 + ML-KEM together
AES-256
GCM at rest & in transit

The practical result is a guarantee few vendors can make honestly: the data you place with us is protected not only against the attackers of today, but against the cryptographic threats of the coming decade.

Data protection & privacy

We protect data by collecting as little of it as possible and isolating what we do hold. Our data-handling controls are built around four commitments:

For the full detail on what we collect, how long we keep it, and your rights over it, see our Privacy Policy.

Application & infrastructure security

Strong cryptography is only as good as the systems around it. We secure the software we ship and the infrastructure it runs on with controls that operate continuously.

Secure development lifecycle

Security is built into how we write software, not inspected in at the end. Changes go through peer code review, automated dependency and vulnerability scanning, and testing before release. We track and remediate known vulnerabilities in our dependencies on a defined cadence, prioritized by severity.

Hardened cloud infrastructure

Our systems run on reputable cloud infrastructure with hardened baseline configurations. Environments are separated, network access is restricted to what each service requires, and administrative surfaces are not exposed to the public internet.

Access controls

Access to production systems follows least privilege and requires strong authentication. Permissions are role-scoped, granted on a need-to-know basis, and reviewed rather than left to accumulate.

Monitoring & audit logging

We monitor our systems for anomalous and unauthorized activity, and we maintain audit logs of significant actions so that events can be investigated and reconstructed. Logging is designed to give us — and, where appropriate, you — a defensible record of what happened and when.

Compliance alignment

Security that cannot be demonstrated is incomplete. We map our controls and evidence to the frameworks that enterprise buyers, auditors, and regulators rely on. To be precise about what this means: our program is aligned to and mapped against these frameworks. We describe our posture accurately and do not claim certifications we cannot substantiate.

For how we help customers reach the same standard in their own AI programs, see our Compliance page.

Responsible disclosure

We welcome the security research community and treat external reports as a valued part of our defense. If you believe you have found a vulnerability in a Deflected system, please report it to security@deflected.ai with enough detail for us to reproduce and validate the issue.

Our commitments to researchers who engage with us in good faith:

We will not pursue good-faith research conducted within these guidelines. If you are unsure whether a specific test is acceptable, ask us first.

Our security promise

The data you entrust to Deflected is protected by post-quantum encryption, strict tenant isolation, and defense-in-depth — engineered to withstand the threats of today and the cryptographic threats of the decade ahead.

Questions about our security?

Talk to our team about how Deflected protects your data — and how we can bring the same standard to your AI layer.