Enterprise Security

Trust Center

Security, Privacy & Compliance at Tork

Last updated: January 17, 2026

Security Overview

Encryption

  • TLS 1.3 for all data in transit
  • AES-256 encryption at rest
  • End-to-end encryption for sensitive data

Infrastructure

  • SOC 2 certified infrastructure providers (Vercel, Supabase)
  • Automatic failover and redundancy
  • DDoS protection and WAF

Access Controls

  • Role-based access control (RBAC)
  • API key authentication with scopes
  • Audit logging of all access

Monitoring

  • 24/7 security monitoring
  • Real-time threat detection
  • Automated vulnerability scanning

Compliance Status

GDPR

Ready

Data Processing Agreement available

Request DPA

CCPA

Compliant

California Consumer Privacy Act

Privacy Policy

HIPAA

Ready

Business Associate Agreement available

Request BAA

POPIA

Compliant

Protection of Personal Information Act (South Africa)

Privacy Policy
🔄

SOC 2 Type II

In Progress

Target completion subject to change

📋

ISO 27001

Planned

Certification planned for Q4 2026

Compliance Roadmap

Q4 2025COMPLETED

Security Foundation

  • Infrastructure hardening
  • Encryption implementation
  • Access controls
Q1 2026COMPLETED

Compliance Documentation

  • DPA published
  • BAA published
  • Privacy policy updates
Q2 2026 (target)IN PROGRESS

SOC 2 Type II

  • Audit preparation
  • Control testing
  • Report generation
Q4 2026PLANNED

ISO 27001

  • ISMS implementation
  • Certification audit
  • Continuous improvement

Data Residency

Primary Data Location

All customer account data, audit logs, and persistent storage is located in AWS us-east-1 (Virginia, USA).

Our database provider (Supabase) maintains SOC 2 Type II certification with encryption at rest and in transit.

API Processing

Content sent to our APIs for evaluation is processed in real-time memory only and is NOT persisted after the API call completes.

Edge functions may process requests at the nearest Vercel edge location for optimal latency.

Regional Deployment: We are actively working on regional deployment options for customers with specific data residency requirements (EU, APAC). Contact us to discuss your needs.

Sub-processors

Sub-processorLocationPurposeData Processed
Vercel Inc.
Global CDN with regional data centers
United StatesApplication hosting and edge deliveryRequest metadata, application logs
Supabase Inc.
AWS us-east-1 (Virginia)
United StatesDatabase hosting and authenticationAccount data, audit logs, API keys
Resend Inc.
AWS us-east-1 (Virginia)
United StatesTransactional email deliveryEmail addresses, notification content
Upstash Inc.
AWS us-east-1 (Virginia)
United StatesRate limiting and caching (Redis)API key hashes, request counters

For a complete list of sub-processors and notification of changes, contact privacy@tork.network to request our Data Processing Agreement.

Legal Documents

Incident Response

We maintain a documented incident response plan to ensure rapid detection, containment, and resolution of security incidents.

72h
GDPR Notification
Data breach reporting
60d
HIPAA Notification
PHI breach reporting
24/7
Response Team
On-call availability

Security FAQ

Cryptographic Governance

HMAC-Signed Receipts

Every AI interaction generates a cryptographic HMAC-signed receipt. These receipts provide tamper-proof evidence of what happened, when, and what governance was applied.

Tamper-Proof Audit Trail

Any modification to a receipt invalidates the signature. Full audit trail: who said what, when, and what governance decisions were made — all cryptographically verifiable.

PII Detection

Credit cards, ID numbers, phone numbers, and email addresses are detected before storage using gravity-weighted multi-layer detection. Sensitive data is flagged and redacted in real-time.

Governance by Default

Every Tork product ships with governance enabled. PII detection, audit receipts, and human escalation paths are on by default — not opt-in afterthoughts.

Responsible AI

At Tork, governance is not optional — it's the default. Every product we ship includes compliance and safety features enabled from day one.

Every Tork product ships with governance enabled
PII detection on by default — credit cards, IDs, phone numbers, emails
Cryptographic audit receipts on by default — every interaction receipted
Human escalation paths on by default — frustration and complaint detection
Your data stays yours — we don’t train on it, we don’t share it

AI Risk Coverage — MIT AI Risk Taxonomy

Tork's governance features mapped against the MIT AI Risk Initiative's 24 risk subdomains. Based on analysis of 1,000+ governance documents by MIT, Georgetown CSET, and FutureTech.

8
Full Coverage
10
Partial Coverage
6
Outside Scope
MIT AI Risk Taxonomy
24 subdomains

Full Coverage

FULL

AI system security vulnerabilities

100/100 security headers, rate limiting, API key authentication, input validation

FULL

Compromise of privacy

50+ PII types detected across 13 regional formats with real-time redaction

FULL

Lack of transparency

HMAC-signed compliance receipts, full audit trails, TORKING-X trust scoring

FULL

Governance failure

Policy-as-code enforcement at runtime — not documents about governance, actual governance

FULL

Overreliance and unsafe use

HITL approval gates, emergency kill switch, ARCH-05 swarm budget limits

FULL

Loss of human agency

Human-in-the-loop workflows, approval gates, configurable escalation policies

FULL

Fraud, scams, manipulation

PII detection prevents data exfiltration, policy enforcement blocks malicious outputs

FULL

Multi-agent risks

A2A, ACP, AG-UI, Consent protocol endpoints. 136 adapters across every major agent framework

Partial Coverage

PARTIAL

Lack of capability/robustness

ARCH-07 behavioral baseline detects anomalies. Hallucination detection planned H2 2026

PARTIAL

False or misleading information

Content policy enforcement blocks known patterns. Hallucination scoring planned

PARTIAL

Unfair discrimination

Policy engine can flag discriminatory patterns. Dedicated bias detection module planned H2 2026

PARTIAL

Cyberattacks and weapons

Input filtering prevents prompt injection. Malicious code detection planned Q3 2026

PARTIAL

Disinformation and surveillance

PII redaction prevents surveillance data leakage. Content policies block manipulation

PARTIAL

Pollution of information ecosystem

Content governance on agent outputs. Quality scoring via TORKING-X

PARTIAL

Exposure to toxic content

Content policy enforcement with block/flag/allow actions

PARTIAL

Unequal performance across groups

Configurable per-org policies. Regional PII formats ensure equal treatment

Outside Middleware Scope

NOT ADDRESSED

Economic and cultural devaluation

Socioeconomic concern — outside runtime governance scope

NOT ADDRESSED

Power centralisation

Structural concern — outside middleware scope

NOT ADDRESSED

Environmental harm

Compute impact — outside middleware scope

NOT ADDRESSED

Competitive dynamics

Market concern — outside middleware scope

NOT ADDRESSED

AI welfare and rights

Philosophical domain — outside middleware scope

NOT ADDRESSED

Increased inequality

Socioeconomic concern — addressed through equitable pricing (NFP 80% discount)

NOT ADDRESSED

AI pursuing own goals

Constrained by policy engine and kill switch. Goal-drift detection via ARCH-07

PARTIAL

AI possessing dangerous capabilities

Swarm budget limits (ARCH-05) and tool governance constrain capabilities

Risk taxonomy based on the MIT AI Risk Repository (airisk.mit.edu). Coverage assessment by Tork Network, April 2026. Subdomains classified as 'Outside Middleware Scope' represent socioeconomic or structural concerns that require policy intervention, not runtime governance.

Trusted by Teams Worldwide

See how organizations use Tork to build safer, more compliant AI systems.

Read customer testimonials →

Security Inquiries

For security questions, vulnerability reports, or to request security documentation, contact our security team.

security@tork.network

For general inquiries, email us at hello@tork.network