Privacy

Privacy answers for buyer review.

Last updated · April 2026

What the platform handles, how review starts, and where to route deeper diligence.

Operator-focused data model Centered on findings, controls, remediation, evidence, and audit workflows.
Explicit AI boundaries AI generation requires explicit provider configuration. No pretending.
Trust review friendly Start from exported evidence, then move into the live product.

Data categories typically involved.

Category Examples Why it appears in isops.ai
Infrastructure & posture AWS findings, resource identifiers, regions, topology relationships Drives posture, remediation, evidence, and reporting workflows
Compliance workflow Policies, controls, CAPA, risks, evidence records, audit notes Supports compliance operations and audit readiness
Operator metadata Assignees, status changes, reviewer notes, narrative context Preserves operational history and audit trail
AI configuration Configured provider choice, user-submitted remediation prompts Supports explicit, operator-controlled copilot generation

Privacy review checklist

  • Validate which environments and frameworks are in scope.
  • Review whether exported evidence or reports include customer-specific identifiers.
  • Confirm whether AI provider configuration will be enabled during the walkthrough.
  • Route subprocessors and security follow-up through the linked trust pages.