Security

Evidence, review, and a documented decision.

AI-assisted analysis. Analyst-owned decisions. Response actions require a documented Human Review Approval timestamp.

Stated posture
  • AWS us-east-1 residency
  • AES-256 at rest
  • TLS 1.3 in transit
  • MFA mandated
  • Immutable audit logs
  • SOC 2 Type II audit in progress

FactPattern is not certified under SOC 2, ISO 27001, GDPR, HIPAA, or PCI.

How it works

Six operating boundaries.

Pillar 01
Human review approval

Response actions require a documented Human Review Approval timestamp.

  • Approval recorded with actor and time
  • Recommendations stay drafts until approved
  • Approvals appear in the audit log
Pillar 02
Read-only intake

Inbound connectors import signals without write access.

  • Read scopes on inbound connectors
  • Outbound use is limited to review-gate notification
  • Connector scope confirmed during access review
Pillar 03
Audit logging

Immutable logs of evidence modifications and review approvals.

  • Evidence modifications recorded
  • Review approvals recorded
  • Records are immutable
Pillar 04
Encryption

AES-256 at rest; TLS 1.3 in transit.

  • Data residency: AWS us-east-1
  • Logically isolated schemas per organization ID
  • Credentials are not displayed after setup
Pillar 05
Source-referenced findings

Every finding references the evidence it relied on.

  • Citations on each statement
  • Confidence gaps are marked, not filled
  • Drafts never execute on their own
Pillar 06
Roles and MFA

Admin, Lead, and Analyst roles.

  • Roles enforced server-side
  • MFA mandated for all accounts
  • Access granted through access review
Operating principle

AI-assisted analysis. Analyst-owned decisions.

FactPattern surfaces relationships and confidence gaps; analysts decide what happens next. No autonomous closure of critical investigations. Every recommendation must point back to source evidence.

Trust and security

Have a security or data processing question?

A Standard Data Processing Agreement is available upon request.

Security questions

Data processing questions and vulnerability reports.

Send security findings and data processing questions here.

Security inquiry
Ask a data processing question, request the Standard Data Processing Agreement, or report a vulnerability.
We respond within one business day. No newsletter spam.

For active vulnerability disclosure, also email [email protected] with details.