TRUST & SECURITY

Your data, protected at every layer

Surface is built to meet the scrutiny of enterprise security teams. Your data is encrypted in transit and at rest, never used to train shared AI models, and protected by controls independently audited against SOC 2 standards.

SOC 2 TYPE II

SOC 3

GDPR

CCPA

RESPONSIBLE AI

Our commitments to you

No training on your data

Your data is never used to train AI models, by Surface or by our model providers. Our enterprise agreements with model providers prohibit training on customer data.

Your data stays yours

We never sell or share customer data. Benchmarks use only anonymized, aggregated insights, and no raw or identifiable data is ever shared with third parties or other customers.

Encrypted everywhere

AES-256 encryption at rest and TLS 1.3 in transit, with additional safeguards for sensitive fields.

Humans stay accountable

Surface provides analysis and recommendations. People remain responsible for the decisions and actions that follow.

No training on your data
Your data is never used to train AI models, by Surface or by our model providers. Our enterprise agreements with model providers prohibit training on customer data.
Your data stays yours
We never sell or share customer data. Benchmarks use only anonymized, aggregated insights, and no raw or identifiable data is ever shared with third parties or other customers.
Encrypted everywhere
AES-256 encryption at rest and TLS 1.3 in transit, with additional safeguards for sensitive fields.
Humans stay accountable
Surface provides analysis and recommendations. People remain responsible for the decisions and actions that follow.

HOW WE PROTECT YOUR DATA

Security controls that hold up to review

Every layer of Surface is designed for enterprise scrutiny, from infrastructure through incident response. Our SOC 2 Type II report covers Security, Confidentiality, and Availability and is audited annually.

HOW WE PROTECT YOUR DATA

Security controls that hold up to review

Every layer of Surface is designed for enterprise scrutiny, from infrastructure through incident response. Our SOC 2 Type II report covers Security, Confidentiality, and Availability and is audited annually.

HOW WE PROTECT YOUR DATA

Security controls that hold up to review

Every layer of Surface is designed for enterprise scrutiny, from infrastructure through incident response. Our SOC 2 Type II report covers Security, Confidentiality, and Availability and is audited annually.

Encryption

AES-256-GCM at rest, TLS 1.3+ in transit, and additional protections for sensitive fields.

Access controls

Role-based access, SSO, 2FA, session timeouts, and quarterly access reviews. Administrative access is provisioned only when required.


Resilient infrastructure

US-based AWS and Railway hosting with daily backups, automatic failover, and continuous monitoring.

Vulnerability management

Annual third-party penetration testing, vulnerability scanning, endpoint security, and intrusion detection.

Incident response

A documented response process, with customers notified of confirmed breaches within 72 business hours.

Continuous monitoring

Security and privacy controls continuously monitored through Secureframe, with policies reviewed against applicable standards.

Encryption
AES-256-GCM at rest, TLS 1.3+ in transit, and additional protections for sensitive fields.
Access controls
Role-based access, SSO, 2FA, session timeouts, and quarterly access reviews. Administrative access is provisioned only when required.
Resilient infrastructure
US-based AWS and Railway hosting with daily backups, automatic failover, and continuous monitoring.
Vulnerability management
Annual third-party penetration testing, vulnerability scanning, endpoint security, and intrusion detection.
Incident response
A documented response process, with customers notified of confirmed breaches within 72 business hours.
Continuous monitoring
Security and privacy controls continuously monitored through Secureframe, with policies reviewed against applicable standards.

RESPONSIBLE AI

Responsible AI, by design

Surface informs decisions. It doesn’t make them. Outputs are grounded in your data, evaluated continuously, and governed by clear principles. Human experts shape how Surface works and regularly review its performance.

RESPONSIBLE AI

Responsible AI, by design

Surface informs decisions. It doesn’t make them. Outputs are grounded in your data, evaluated continuously, and governed by clear principles. Human experts shape how Surface works and regularly review its performance.

RESPONSIBLE AI

Responsible AI, by design

Surface informs decisions. It doesn’t make them. Outputs are grounded in your data, evaluated continuously, and governed by clear principles. Human experts shape how Surface works and regularly review its performance.

Grounded in your data

Outputs draw on your organization’s data and context, with safeguards against hallucinations, prompt injection, and sensitive-data exposure.

Continuously evaluated

Outputs are continuously evaluated for factuality, relevance, completeness, and safety through automated testing and human review.

You stay in control

Surface explains its analysis and recommendations so your team can review the reasoning, apply judgment, and decide what action to take.

Governed by principle

Our approach is grounded in the OECD AI Principles, with clear standards for fairness, transparency, robustness, and accountability.

Grounded in your data
Outputs draw on your organization’s data and context, with safeguards against hallucinations, prompt injection, and sensitive-data exposure.
Continuously evaluated
Outputs are continuously evaluated for factuality, relevance, completeness, and safety through automated testing and human review.
You stay in control
Surface explains its analysis and recommendations so your team can review the reasoning, apply judgment, and decide what action to take.
Governed by principle
Our approach is grounded in the OECD AI Principles, with clear standards for fairness, transparency, robustness, and accountability.

Questions your security team will ask

What data do we share with Surface?
Only what you choose to. Surface can process account and user information, workforce and HRIS data, survey and performance data, training and program participation data, content your users submit (prompts, documents, and AI inputs and outputs), and data from connected systems — but you control what's uploaded, which systems connect, and whether to include personal identifiers. Surface supports both identified and de-identified deployments, so sharing names or emails is always optional.
Only to deliver, operate, and improve the services you've requested — generating AI-powered insights, analytics, benchmarking, and recommendations. In identified mode, Surface can link data across systems and analyze trends at the individual level; in de-identified mode, you still get organization-, team-, and demographic-level analytics and benchmarking. Either way, Surface processes only what you provide, and only to deliver the contracted services.
No. Your data is never used to train AI models — not by Paradigm, and not by OpenAI or Anthropic, whose enterprise contracts prohibit training on customer data.
In the US: customer files live in AWS S3 and all other data runs on Railway's cloud infrastructure, across physically secure data centers. Everything is encrypted at rest (AES-256) and in transit (TLS 1.3). Transfers from the EEA, UK, and Switzerland are governed by EU and UK Standard Contractual Clauses.
Surface is a closed application: your admins provision every user, and no data is publicly accessible without a provisioned account. SSO and 2FA are supported, access is role-based down to the data level, and access reviews run quarterly.
Paradigm holds SOC 2 Type II certification, renewed annually, covering Security, Confidentiality, and Availability. A public SOC 3 report is available for download, we maintain GDPR and CCPA compliance, and controls are continuously monitored by Secureframe. Third-party penetration tests run annually.
Your data is deleted within 6 months of the agreement ending, or sooner on written request, and we'll provide written certification of deletion.
No. AI outputs are advisory and should be human-verified before acting. Surface informs decisions; it doesn't make them — and it will never tell you whom to hire or promote.
With a proactive, multi-layered approach: automated evaluation across factuality, grounding, relevance, completeness, and safety; adversarial prompt testing; and ongoing human spot-checks. Outputs are re-evaluated whenever models, prompts, or data sources change, and you can request our bias evaluation methodology for high-risk use cases.
Key subprocessors for Surface include AWS and Railway (hosting), WorkOS/Okta (SSO and identity), Merge (HRIS integration), and OpenAI and Anthropic (AI processing) — all US-based and contractually bound to our DPA obligations. The full, current list is on our Trust Center.

Bring your security team

See how Surface handles data, access, and governance — and get your review questions answered by the people who built it.

Request a Demo

Bring your security team

See how Surface handles data, access, and governance — and get your review questions answered by the people who built it.

Request a Demo