Trust

Security at GuardenerAI

Last updated: July 5, 2026

GuardenerAI was hardened in healthcare first, where data has to be spotless and protected. The practices below apply to every customer on the platform today.

Encryption everywhere

Tenant isolation

Every customer workspace lives in its own isolated database schema. Queries are scoped to your tenant by construction, and tenant subdomains are bound to your workspace at the edge.

Access control

Audit trail

Security-relevant actions and record changes are written to an append-only audit log that cannot be quietly edited, with change-source attribution for automated and AI-driven edits.

AI data handling

The built-in assistant runs against your workspace only, inside our AWS environment (Amazon Bedrock). Your data is not used to train third-party foundation models, and per-tenant AI credentials are isolated and KMS-encrypted.

Infrastructure and resilience

Compliance roadmap

GuardenerAI is built with healthcare-grade practices, and HIPAA compliance (including BAAs) and SOC 2 Type II are on our active roadmap. If you need to store regulated health information, talk to us first so we can discuss timing and the right agreement before you onboard that data.

Reporting a vulnerability

If you believe you've found a security issue, email hello@guardenerai.com with the details. We read every report and will respond promptly.