Trust and security

What we can state, stated plainly.

This page lists only confirmed facts about how FactPattern is operated. Anything not listed here is not claimed.

Infrastructure and data

Infrastructure and data

Data residency

AWS us-east-1 (Northern Virginia).

Encryption

AES-256 at rest; TLS 1.3 in transit.

Tenant isolation

Logically isolated schemas per organization ID.

Access and accountability

Access and accountability

Access control

Admin, Lead, and Analyst roles; MFA mandated for all accounts.

Audit logging

Immutable logs of evidence modifications and review approvals.

Human boundary

Response actions require a documented Human Review Approval timestamp.

AI

AI

AI model provider

OpenAI GPT-4o via Azure OpenAI Service.

Model policy

Customer signals are not used to train the foundation model; customer-data training uses a zero-retention policy.

Audit and transfers

Audit and transfers

SOC 2 Type II

Audit in progress; audit window started Q1 2026.

GDPR transfer mechanism

Standard Contractual Clauses (SCCs).

Scope of these statements

FactPattern is not certified under SOC 2, ISO 27001, GDPR, HIPAA, or PCI. The SOC 2 Type II audit is in progress. Standard Contractual Clauses are a transfer mechanism, not a certification.

FactPattern organizes evidence and review decisions so teams can evaluate their own controls and reporting needs.

Security & legal
Security and legal questions

Vulnerability reports, data processing questions, and legal correspondence.

[email protected]
Customer support
Support and onboarding questions

Setup help, connectors, and access review coordination.

[email protected]
See the workflow

Walk through a sample matter.

Every demo frame is an illustrative sample — not customer data or a production investigation.