Trust

Security at GuardenerAI

Last updated: August 2026

GuardenerAI holds the records a business runs on: its customers, its contracts, and its money. We were built in healthcare first, where nothing less than careful is acceptable, and that standard did not change when we opened the platform to everyone else.

How we approach it

Security is part of how the product is built rather than a layer added afterwards. Your data is encrypted in transit and at rest. Each customer workspace is isolated from every other. Access is denied by default and granted deliberately, with multi-factor authentication available to every user. Security-relevant actions and record changes are written to an audit trail that cannot be quietly edited, including changes made by automations and by the AI assistant.

The assistant works only against your own workspace, under the same roles and the same audit trail as everything else, and your data is not used to train third-party foundation models. The platform is hosted in the United States, with regular backups and continuous monitoring.

We keep the specifics of our architecture, tooling, and controls out of public view on purpose. If your security team needs detail, we will go through it with them directly.

Security partnership

Security is shared work.

We are responsible for the platform your data sits on. You are responsible for who you let into your workspace and what they can reach. Both halves have to hold, so we make our half easy to verify and your half easy to run.

What we look after

The platform itself: keeping your data encrypted and isolated, keeping the software patched, monitoring what runs, and recording what happened. This is our side of the agreement and it applies on every plan, including the free one.

What you control

Who has an account, what role each person holds, and when access is taken away. Turn on multi-factor authentication, review your member list when people join or leave, and keep admin rights with the few who need them.

Working with your team

Bring us your security questionnaire, your review call, or your procurement checklist. You will talk to the people who build the platform, and we will answer in detail privately, including the things this page deliberately leaves out.

Need a security review before you commit? Talk to us.

Assurance and certifications

GuardenerAI is built to the controls an independent audit examines: encryption in transit and at rest, workspace isolation, least-privilege access, multi-factor authentication, and an audit trail that cannot be quietly edited. These are in place today, on every plan and every account, not held back for an enterprise tier.

Our control set is mapped to the ISO 27001 Annex A framework. We will walk your security team through that mapping, along with our architecture and review standards, under NDA.

Where a procurement process calls for a SOC 2 Type II report, we engage an independent CPA firm specialising in AWS environments and scope the audit against your requirements and your timeline. Raise it early in the conversation and we will put scope, dates, and commitments in writing.

If you plan to store regulated data of any kind, talk to us first so the right terms are agreed before that data is onboarded.

Reporting a vulnerability

If you believe you have found a security issue, email hello@guardenerai.com with enough detail for us to reproduce it. We read every report, we will confirm receipt, and we will keep you updated while we work on it. We will not pursue action against anyone who reports a genuine issue in good faith and gives us reasonable time to fix it.