SplendensLabs

Trust & governance

Audit-ready, day one.

Security, compliance, and responsible-AI posture aren't afterthoughts at Splendens. ISO 27001 / SOC 2-aligned controls, role-aware audit logs, and model evaluation pipelines that survive a regulator's questions.

ISO 27001-alignedSOC 2 Type II readinessGDPR + India DPDPRole-aware auditResponsible AI
See our stack
ISO
27001-aligned controls
SOC 2
Type II posture
DPDP
India-ready
Audit
Logged, role-aware

Built with teams who operate at scale

HealthcareFinancial servicesManufacturingRetail & CPGEnergyPublic sector

Trust, security & responsible AI

The same rigor we apply to models applies to how they're hosted, accessed, and governed — so legal, risk, and engineering stay aligned.

GDPR-ready workflowsSOC 2–aligned controlsAudit logs by defaultVendor DPAs available

Encryption everywhere

TLS 1.3 in transit, KMS-backed keys at rest, and tenant-isolated secrets — aligned with your InfoSec checklist.

Identity & least privilege

SSO / OIDC, RBAC, and scoped service accounts so humans and agents only touch what they must.

Private & air-gapped paths

VPC peering, dedicated tenancy, and on-prem inference where regulation demands it.

Compliance roadmap

GDPR-aware flows, HIPAA-aware deployments for healthcare, and SOC 2 Type II–aligned controls with audit trails.

Responsible AI & governance

Shipping fast doesn't mean shipping blind. We embed evaluation, oversight, and traceability into the release path — not as an afterthought.

  • Evaluation & benchmarks

    Task-specific scorecards, regression suites on golden sets, and domain-expert rubrics — not a single accuracy number.

  • Adversarial review

    Prompt injection and jailbreak testing, plus scenario libraries mapped to your abuse policies.

  • Human oversight

    Configurable review queues when confidence is low or stakes are high — auditable decisions.

  • Lineage & reproducibility

    Dataset versioning, model cards, and deployment manifests so every answer traces back to a known artifact.

Controls matrix

What your security team will ask, and our answer

We've shipped Splendens products into healthcare, fintech, and education enterprises — every one scrutinised our posture. Here's the audit-ready summary, plus the security FAQ that usually shortens the vendor-review cycle by a couple of weeks.

Control areaSplendens postureEvidence on request
Identity & accessStateless JWT + role-based access on every Splendens serviceEductate SecurityConfig, BloomCRM RBAC, JIT access reviews quarterly
Data residencyMySQL / Postgres + S3-compatible buckets, region-pinned per customerDPA addendum specifies region; on-prem option for regulated workloads
EncryptionTLS 1.3 in transit, AES-256 at rest, KMS-managed keysCloud-provider KMS or Hashicorp Vault, customer-managed keys on request
Audit loggingTamper-evident audit log on every write across BloomCRM-connected productsImmutable storage, 7-year retention default, exportable to your SIEM
Vulnerability mgmtDependabot + Snyk + monthly patch SLA, quarterly penetration testsLatest pen-test summary available under NDA
AI governanceEval harness + red-team runs every release; provider-agnostic architectureAI provider switch is an env var; no model lock-in, full prompt logs
PrivacyGDPR-aligned + India DPDP-aware, DSR endpoints on customer-facing surfacesDPIA template, consent journals, and processor list on request
Business continuityRPO ≤ 1h, RTO ≤ 4h on production tiers; multi-AZ by defaultTested DR drills twice a year, runbooks shared with customer SRE

Security FAQ

Where is customer data stored?

Region-pinned at provisioning. India workloads land in ap-south-1 / asia-south1 by default; EU/US/APAC available on request. On-prem is supported for regulated workloads — we ship the same containers everywhere.

Do you train AI models on our data?

No. Splendens is provider-agnostic; the LLM call is a stateless inference round-trip with the providers' data-processing agreements honoured (no training on customer prompts). Self-hosted open models are an option when zero data egress is required.

Can we bring our own keys / model / cloud?

Yes to all three. Customer-managed keys via KMS, model swap by env var, and the same Spring Boot + Next.js + FastAPI stack runs on AWS, GCP, Azure, or on-prem.

What happens if we need to leave?

Data export endpoints are part of every Splendens product (CSV / JSON / SQL dump). The stack is open — Spring Boot, MySQL, Postgres, Next.js — so there's no proprietary runtime to migrate off.

Ready to shape your next AI chapter?

Tell us about your domain, constraints, and timelines. We'll respond with a concrete path — workshop, pilot scope, or referral if we're not the right fit.

Typical response within two business days · NDAs welcomed