Evidence, review, and a documented decision.
AI-assisted analysis. Analyst-owned decisions. Response actions require a documented Human Review Approval timestamp.
- AWS us-east-1 residency
- AES-256 at rest
- TLS 1.3 in transit
- MFA mandated
- Immutable audit logs
- SOC 2 Type II audit in progress
FactPattern is not certified under SOC 2, ISO 27001, GDPR, HIPAA, or PCI.
Six operating boundaries.
Response actions require a documented Human Review Approval timestamp.
- Approval recorded with actor and time
- Recommendations stay drafts until approved
- Approvals appear in the audit log
Inbound connectors import signals without write access.
- Read scopes on inbound connectors
- Outbound use is limited to review-gate notification
- Connector scope confirmed during access review
Immutable logs of evidence modifications and review approvals.
- Evidence modifications recorded
- Review approvals recorded
- Records are immutable
AES-256 at rest; TLS 1.3 in transit.
- Data residency: AWS us-east-1
- Logically isolated schemas per organization ID
- Credentials are not displayed after setup
Every finding references the evidence it relied on.
- Citations on each statement
- Confidence gaps are marked, not filled
- Drafts never execute on their own
Admin, Lead, and Analyst roles.
- Roles enforced server-side
- MFA mandated for all accounts
- Access granted through access review
AI-assisted analysis. Analyst-owned decisions.
FactPattern surfaces relationships and confidence gaps; analysts decide what happens next. No autonomous closure of critical investigations. Every recommendation must point back to source evidence.
Have a security or data processing question?
A Standard Data Processing Agreement is available upon request.
Data processing questions and vulnerability reports.
Send security findings and data processing questions here.
For active vulnerability disclosure, also email [email protected] with details.