Germinate.ai

Security

Security at Germinate

Last Updated: August 2, 2026

Our platform runs on data our clients cannot afford to leak. Security isn't a feature we added — it's a constraint we designed around. This page describes how we protect the environment your agents run in and the data they work from.

Infrastructure

The Germinate platform is built and operated on Amazon Web Services (AWS), whose data centers maintain independent certifications and attestations including SOC 1, SOC 2, ISO 27001, and FedRAMP for the infrastructure layer. On top of that foundation, our environment is managed by a dedicated infrastructure team responsible for hardening, monitoring, and maintaining it.

Private tenancy. Every client gets a private workspace tenancy, isolated from every other client's environment. Your data, agent configurations, prompts, and knowledge bases are private to your tenant.

Least-privilege access. Access to client environments is restricted to the personnel who need it to deliver the agreed services, and no further.

Encryption. Data is encrypted in transit and at rest.

Monitoring and logging. The environment is monitored for availability and anomalous activity, and deployed agents run with monitoring, defined escalation paths, and failure triage.

SOC 2

We are currently undergoing a SOC 2 examination of the Germinate environment. Our control environment is being built against the SOC 2 Trust Services Criteria, and our AI governance practices are organized around the NIST AI Risk Management Framework (AI RMF 1.0). — see our Responsible AI page. Until our report is available, we're happy to walk qualified prospects through our security practices under NDA. Contact security@germinate.ai.

Data Handling

Your data stays yours. Client data is used only to provide the agreed services, under a limited license that ends when the agreement does. We never train AI models on client data — not for our own use, not for any other customer's benefit.

Retention and exit. On termination, your data is available for export for thirty days, after which it is deleted from the platform. Retention controls during the engagement are available where you need them.

Personal data. Where the services involve personal data subject to privacy laws, we execute a data processing addendum. See our Privacy Policy for how we handle website data.

Model choice. You choose the AI models your agents use. Model providers are third parties; we configure agents so client data flows only where the engagement requires.

People and Process

Accountable ownership. Security and AI governance policies have a named accountable owner (our CISO), a defined review cadence, and a change log.

Personnel. Team members with access to client environments are bound by confidentiality obligations.

Agent-level safety. High-impact agents ship with human-in-the-loop checkpoints by default, and an uncertain agent is designed to escalate, not improvise.

Incident response. If something goes wrong, you get a person who is responsible — not a support queue.

Reporting a Vulnerability

If you believe you've found a security vulnerability in the Germinate platform or website, tell us at security@germinate.ai We appreciate good-faith reports and will respond promptly.

Questions

Security reviews, questionnaires, or documentation requests: security@germinate.ai — or raise it in your Readiness Conversation.

This page describes our current practices. It is not a warranty, and nothing here overrides the terms of a signed agreement between Germinate and a client.

Get Started
Contact security@germinate.ai