Security & Trust

Built for enterprise security teams.

Everything a security team needs to know about how InspectModular stores, processes, and protects your AI agent audit data.

Compliance posture
EU AI Act Article 50SOC 2 Type II alignedHIPAA controlsISO 27001 alignedGDPR compliant

InspectModular is designed to meet the requirements of AI governance regulations and enterprise security frameworks. Every audit event is immutable, SHA-256 signed, and tamper-evident at the database level.

Service Level Agreement
API Uptime
99.9% monthly uptime for /api/v1/* endpoints. Measured on a rolling 30-day basis.
Policy Check Latency
p95 under 120ms globally. InspectModular uses Cloudflare edge network for sub-100ms checks worldwide.
Incident Response
Critical incidents acknowledged within 30 minutes. Status published at status.inspectmodular.com.
Data Retention
Audit logs retained for 90 days (standard) and unlimited for enterprise. Exports available at any time.
Fail-Closed Mode
If the InspectModular API is unreachable, agents are blocked by default. No silent failures. Every block is logged.
Planned Maintenance
Notified 72 hours in advance via email and status page. Maintenance windows are under 30 minutes and scheduled off-peak.
Data & residency
Storage
Supabase (PostgreSQL) hosted on AWS us-east-1. EU region available for enterprise customers on request.
Encryption at rest
AES-256 encryption for all stored data. Supabase Vault used for secrets management.
Encryption in transit
TLS 1.3 for all connections. HSTS enforced. Certificates rotated automatically.
Data isolation
Each organization has a dedicated workspace_uuid. Row-level security enforced at the database layer.
Source code
Audit events are structured metadata only. No source code, file contents, or prompts are stored by InspectModular.
Backups
Point-in-time recovery enabled. Daily snapshots retained for 30 days. Enterprise customers can request dedicated backups.
Access control
Authentication
Magic link email authentication. No passwords stored. Sessions expire after 7 days of inactivity.
API keys
Scoped API keys with per-key permissions. Keys are hashed before storage. Revokable at any time from the dashboard.
Admin access
InspectModular staff access to customer data requires internal approval and is logged. Customers can request an access log at any time.
Role-based access
Admin and member roles within each organization. Admins control policy, API keys, and team membership.
Audit & immutability
Tamper-evident logs
Every audit event has a SHA-256 content hash computed on insert. The hash is stored alongside the event and can be verified independently.
Immutable storage
Delete and update operations are blocked at the database level for audit_events. Records can only be appended.
Signed exports
CSV and JSON exports include a manifest with row hashes. Exports can be verified against the stored hashes at any time.
EU AI Act Article 12
InspectModular's audit trail satisfies Article 12 requirements: automatic, lifecycle-long, tamper-evident logging of every AI agent action.
Responsible disclosure

If you discover a security vulnerability in InspectModular, please report it to security@inspectmodular.com. We will acknowledge your report within 24 hours and work with you on a coordinated disclosure timeline. We do not pursue legal action against researchers acting in good faith.