NobleCloak Trust Center
This is the same grid we use to assess third-party AI vendors, answered about ourselves. Every affirmed claim carries a citation and the date we last verified it. A dash means we cannot affirm it — we publish the gap rather than a hedge.
Machine-readable: trust-profile.json
AI risk, data handling & security
| Attribute | Our answer | Source | Verified |
|---|---|---|---|
| Trains on customer data by default | No | AWS Service Terms § Bedrock | |
| Training-use opt-out mechanism | Not applicable no default training | AWS Service Terms § Bedrock | |
| Data residency options Inference routing is pinned to US regions at the IAM boundary and fails closed rather than falling back to another region. This is a code-enforced routing control, not a contractual at-rest data-residency commitment. | — | — | |
| Tenant isolation model Architecture documented across five isolation tiers. A dedicated single-tenant deployment is provisioned per engagement, not a self-serve or currently-running purchase. | Dedicated single-tenant availableOn request | NobleCloak Security Overview | |
| Deployment models offered Architecture documented across five isolation tiers. Dedicated-account and on-premises deployments are provisioned per engagement. | SaaS multi-tenant, Dedicated cloud, On premisesOn request | NobleCloak Security Overview | |
| Underlying model providers | Anthropic | NobleCloak Subprocessors | |
| Model hosting architecture | Third party hosted apis | NobleCloak Subprocessors | |
| Cloud infrastructure providers | AWS | NobleCloak Subprocessors | |
| Subprocessor list published | Yes | NobleCloak Subprocessors | |
| Subprocessor list URL | https://trust.noblecloak.com/policies/subprocessors | NobleCloak Subprocessors | |
| Model/system cards published NobleCloak does not develop foundation models. Model and system cards for the models we consume are published by their developers. | N/A | — | |
| FedRAMP status NobleCloak does not currently sell to US federal agencies, so no FedRAMP designation applies. | N/A | — | |
| SOC 2 report period end No SOC 2 report has been issued, so there is no report period. | N/A | — | |
| SOC 2 attestation Our SOC 2 program has not started. We will publish dates when it does. | — | — | |
| Cyber insurance disclosed Cyber liability coverage will be bound before the platform serves live customers. | — | — | |
| Sells or shares customer data | No | NobleCloak Privacy Policy | |
| Vulnerability disclosure program | Disclosure policy only | NobleCloak Vulnerability Disclosure Policy | |
| Zero-data-retention mode available | — | — | |
| Customer content retention window | — | — | |
| Human review of customer content | — | — | |
| Customer-managed encryption keys | — | — | |
| Contractual deletion window after termination | — | — | |
| Encryption at rest | — | — | |
| Encryption in transit | — | — | |
| ISO/IEC 27001 certified | — | — | |
| ISO/IEC 42001 certified | — | — | |
| HIPAA BAA available | — | — | |
| Data Privacy Framework certified | — | — | |
| DPA offered | — | — | |
| Output IP ownership | — | — | |
| Output copyright indemnification | — | — | |
| Uptime SLA | — | — | |
| SSO (SAML/OIDC) support SSO is included on our first paid tier. The registry enum cannot yet express that, so we make no coded claim rather than assert a value that would misrepresent our posture in either direction. | — | — | |
| SCIM provisioning | — | — | |
| Audit log availability Logs are viewable in-product (org-scoped Execution Ledger) and exportable as CSV. We render the conservative in_product_only rung rather than api_or_siem_export; whether the CSV export qualifies as the stronger tier is a call for the claim owner, not an inference from the code alone. | In product only | NobleCloak Security Overview | |
| Third-party penetration testing | — | — | |
| BC/DR program documented | — | — |
Public signals
| Attribute | Our answer | Source | Verified |
|---|---|---|---|
| Trust center URL | https://trust.noblecloak.com | NobleCloak Trust Center | |
| Public breach disclosure This attribute is assert-true-only: a claim appears here only when there is a disclosed breach to report. Its absence means no such event has been disclosed, not that we decline to answer. | — | — | |
| Regulatory enforcement action This attribute is assert-true-only: a claim appears here only when there is a disclosed regulatory enforcement action to report. Its absence means no such action has been disclosed, not that we decline to answer. | — | — | |
| security.txt published | Yes | NobleCloak security.txt | |
| Public status page | — | — | |
| Most recent disclosed security incident This attribute is assert-true-only: a date appears here only when there is a disclosed security incident to report. Its absence means no such incident has been disclosed, not that we decline to answer. | — | — |
Company
| Attribute | Our answer | Source | Verified |
|---|---|---|---|
| Headquarters country | US | NobleCloak Privacy Policy | |
| Year founded | 2026 | NobleCloak Privacy Policy | |
| Parent company NobleCloak is independently owned and has no controlling parent. | N/A | — | |
| Ownership structure Ownership structure will be published with a citation once a company/about page states it directly. | — | — |