FormationDocumentsComplianceOwnershipGovernance
Log InSign Up

Trust & Security

Effective Date: August 17, 2026

You are trusting EntityEngine with your formation documents, your board's minutes, your cap table, and in some cases your Social Security Number. Here is how we protect them.

Your Data Belongs to You

You own everything you put into EntityEngine. We do not sell it, we do not use it to train AI models, and we do not mine it for advertising. If you leave, you can export it, and we delete it on request — subject only to filing records we are legally required to retain.

Encryption

  • In transit — TLS on every connection.
  • At rest — all data is encrypted at rest using Google Cloud's managed encryption.
  • Secrets — credentials, API keys, integration tokens, and multi-factor authenticator secrets are encrypted with per-purpose keys and stored in Google Secret Manager, never in source code.
  • Social Security Numbers — encrypted with a dedicated key, in their own field, separate from the rest of the application record. Deleted as soon as the EIN is issued; only the last four digits are retained.

Access Control

  • Multi-factor authentication is available on all accounts, with authenticator secrets encrypted at rest.
  • Role-based permissions govern every record. Board, committee, executive, staff, and external roles see different things.
  • Per-organization isolation. Every query is scoped to your organization at the data layer.
  • Least-privilege production access. Only personnel who need production access have it, and that access is logged.
  • Audit trails record who accessed and changed governance records, decisions, and documents.

AI Security

This is where most of our customers have questions, so we are specific.

  • AI features run on Google Cloud Vertex AI (Gemini) under enterprise terms, in United States regions.
  • Your content is never used to train any AI model — not ours, not Google's, not a third party's. Google Cloud's enterprise terms prohibit it.
  • Each organization has its own retrieval corpus. Queries are filtered to your organization before any content is retrieved.
  • Role filtering happens before reasoning, not after. If a staff member asks a question, board-only material is excluded from retrieval rather than retrieved and then withheld. When the system cannot resolve a user's role, it defaults to the most restrictive access.
  • Social Security Numbers and payment details are never placed in AI prompts or corpora.

Application Security

  • Automated dependency scanning with alerts on known vulnerabilities.
  • Secret scanning on every commit, blocking credentials from entering the repository.
  • Code review required on every change before it reaches production.
  • An automated test suite gates deployment, including tests dedicated to tenant isolation and access control.

Availability and Recovery

  • Hosted on Google Cloud Run with managed autoscaling and health checks.
  • Managed PostgreSQL with automated backups and point-in-time recovery.
  • A documented rollback procedure. Our first response to a production incident is to revert to the last known-good release, not to debug forward.
  • Deployment is gated on health verification before traffic shifts.

Incident Response

If we detect a security incident affecting your data, we will:

  • Contain it and revert to a known-good state.
  • Investigate scope and root cause.
  • Notify affected customers without undue delay, and within any deadline the applicable state breach-notification law sets.
  • Tell you what happened, what data was involved, what we did, and what you should do.
  • Publish a post-incident summary for material incidents.

Reporting a Vulnerability

Email security@entityengine.ai. We will acknowledge within 3 business days. We do not pursue legal action against good-faith security research conducted under this policy. Please do not access other customers' data, degrade the service, or publicly disclose before we have had a reasonable chance to fix the issue.

Compliance

We would rather tell you where we actually are than imply more.

  • SOC 2 — we are not certified today. We are happy to walk through our controls in detail.
  • CCPA and CPRA — a Data Processing Addendum is available on request. See our Privacy Policy.
  • Data residency — we operate entirely in the United States, and so do all of our subprocessors.
  • PCI DSS — card data is handled entirely by Stripe. We never receive full card numbers.
  • Subprocessors — published at entityengine.ai/subprocessors, with 30 days' notice before changes.

Questions

Security questionnaires, Data Processing Addenda, and architecture questions: security@entityengine.ai.

Platform

OverviewEntityMax AISecurity & AuditPricing

Formation

LLCCorporationNonprofit501(c)(3) Determination

Governance

Meetings & AgendasVoting & ResolutionsDocumentsE-SignaturesEquity & Cap Table

Compliance

Federal BOI StatusRegistered AgentLicense Intelligence

Resources

Information CenterLicense LibraryState Filing GuidesTax RegistrationBusiness BlogCompare EntityEngine

Company

AboutPricingContact
Join our PlatformSchedule a DemoStart Any FormationGet Your EIN #Get Your 501(c)(3) Determination
© 2026 EntityEngine, Inc.
Privacy PolicyTerms of Service