Trust Center · Last Updated March 2026

Security is not just what we build —
it's how we operate.

You're trusting us with access to your source code. We take that seriously. This page documents exactly how we handle your data, protect your code, and keep our own platform secure.

Certifications
ISO 27001 SOC 2 PCI-DSS GDPR
📋
Compliance Layer
ISO 27001 · SOC 2 · PCI-DSS
Certified
🔒
Data Protection
Encryption · Zero Code Storage
Active
🧠
AI Safety
In-House Models · No 3rd Party LLMs
Verified
🖥️
Infrastructure
AWS · UK Region · Private VPC
Hardened
🐛
Vulnerability Disclosure
HackerOne · Responsible Process
Open
✓ GDPR Aligned ✓ Air-Gap Ready ✓ On-Premises

Security posture

Our core commitments to every customer

🔐

Code Never Stored Permanently

Your source code is analyzed in ephemeral, isolated environments. We retain only the security findings — not the code itself. Scan jobs are destroyed after analysis completes.

✓ Active Policy
🛡️

Encrypted in Transit & at Rest

All data in transit uses TLS 1.3. Findings and metadata stored at rest are encrypted using AES-256. Encryption keys are managed via a dedicated key management service.

✓ Always Encrypted
🔍

Full Audit Logging

Every scan, every finding access, every user action is logged with immutable audit trails. SIEM integration available for teams that need to pull logs into their own systems.

Available on Ultimate
🧪

Penetration Tested

AquilaX undergoes regular third-party penetration testing. We eat our own dog food — our own platform runs AquilaX scans on every commit to our codebase.

✓ Annual 3rd Party Pentest
🌍

GDPR & UK GDPR Compliant

AquilaX LTD is a UK-registered company. We process data in accordance with UK GDPR and EU GDPR. EU-region SaaS deployment available for data residency requirements.

✓ GDPR Aligned
🏗️

On-Premises Available

Your most sensitive code never leaves your network. AquilaX on-premises deploys all 32 scanners inside your infrastructure — air-gapped environments supported.

Available on Ultimate

How we handle your code

A transparent view of the code scanning lifecycle

1

Repository Access

AquilaX requests read-only access to your repositories via OAuth. We never request write permissions. Tokens are encrypted and stored with rotation policies.

2

Code Fetched

Code is fetched into an isolated, ephemeral container for each scan. The container is network-isolated and destroyed after scanning completes.

3

32 Scanners Run

All 32 scanners analyze the code in parallel within the isolated environment. No code leaves the container during analysis.

4

Findings Stored

Only the security findings (file paths, line numbers, vulnerability descriptions) are stored — encrypted. Source code is discarded.

5

Container Destroyed

The ephemeral scan container and all temporary files are cryptographically wiped after each scan. Your code exists in our infrastructure only during the scan window.

What we store vs. what we don't

✅ What we store (findings only)

  • • File path and line number of findings
  • • Vulnerability type and severity classification
  • • Remediation suggestions
  • • Security Rating scores over time
  • • Scan metadata (timestamp, duration)

❌ What we never store

  • • Your source code
  • • Secrets or credentials found during scanning
  • • PII data identified by scanners
  • • Any plain-text code snippets

AI Safety & Privacy Principles

How Securitron AI handles your code — and what it doesn't do

🏢

In-House AI Engines

Securitron AI operates exclusively within AquilaX-owned data centres. Your code is never sent to third-party AI providers (OpenAI, Anthropic, etc.) — our AI runs entirely in-house.

🚫

No Third-Party Data Sharing

Customer data is never shared with third parties. We use open-source AI models where licences allow, but internally gathered security intelligence is never shared with any third-party dataset.

🗑️

Right to Delete

Customers have the right to delete some or all of their information from our systems at any time. Data deletion requests are processed promptly — no retention after deletion.

🎯

Cybersecurity-Focused AI

Securitron AI is tailored specifically for the cybersecurity space — trained on over 300 million projects to reduce noise and computational demands. Not a general-purpose LLM pointed at code.

CPU-Efficient by Design

Our AI models are designed to be CPU-friendly, enabling full on-premises installations without GPU infrastructure requirements — essential for air-gapped government and defence deployments.

📖

AI Principles Published

Our full AI and engineering principles are publicly documented at docs.aquilax.ai. Transparency is a non-negotiable principle for us.

Compliance frameworks we help you achieve

AquilaX generates audit-ready evidence packages for the most common frameworks

SOC 2 Type II
Security & Availability
✓ Evidence Generation
PCI-DSS v4
Payment Card Security
✓ Requirement 6 (AppSec)
HIPAA
Healthcare Data
✓ Technical Safeguards
ISO 27001
Information Security
✓ Annex A Controls
NIST CSF
Cybersecurity Framework
✓ Identify & Protect
OWASP ASVS
AppSec Verification
✓ Level 1, 2, 3
CIS Benchmarks
Security Configuration
✓ Container & IaC
GDPR / UK GDPR
Data Protection
✓ PII Detection

Deployment options for every requirement

🖥️ On-Premises

On-Premises / Air-Gapped

Deploy the full platform inside your network. Your code never leaves your perimeter.

  • All 32 scanners available on-premises
  • Air-gapped network support
  • Docker / Kubernetes deployment
  • Zero data egress — code stays local
  • Single license, no per-seat fees
  • Government & defence approved

Responsible Disclosure

Found a vulnerability in AquilaX?

We believe in working with the security community to keep our platform and customers safe. If you discover a security vulnerability in AquilaX, we ask that you report it responsibly — we'll acknowledge receipt within 24 hours and work with you on a coordinated disclosure.

What to include in your report

  • • Affected component or endpoint
  • • Steps to reproduce
  • • Potential impact assessment
  • • Your preferred contact method

Our commitments to you

  • • 24h acknowledgement
  • • 90-day coordinated disclosure timeline
  • • Credit in our security acknowledgements
  • • No legal action for good-faith reports

Report vulnerabilities to: [email protected]

Contact Security Team
Questions About Our Security Posture?

Transparency is a feature,
not an afterthought.

Have specific questions about how AquilaX handles your code? Need a security questionnaire completed? Our team is happy to provide detailed answers.

Talk to Our Security Team → Start Free Scan