Skip to main content

Trust center

Everything your security review is about to ask for

Certifications, controls, subprocessors and audit reports, published here rather than behind a vendor portal. The confidential documents are one request away.

Certifications

Audited, not self-attested

Independent auditors test our controls on a schedule.

  • Certified

    SOC 2 Type II

    Security, availability and confidentiality controls, tested across a full audit window rather than at a single moment.

    Under NDA

  • Certified

    ISO/IEC 27001:2022

    Information security management: risk assessment, supplier management, access control, incident response. Certified against the 2022 revision.

    Under NDA

  • Certified

    ISO/IEC 42001:2023

    How we build, evaluate and monitor the AI in Reos, including impact assessment and human oversight of AI output.

    Under NDA

  • Compliant

    GDPR

    A DPA with Standard Contractual Clauses, a record of processing activities, a transfer impact assessment, and data subject requests answered on time.

    DPA on request

Confidential documents

Request the reports under NDA

The confidential documents are shared under a short mutual NDA. Request access with a Reos account, sign in your browser, and they open at once. No sales call.

4 documents under NDA

Access lasts 90 days and is renewable.

  1. RequestSign in and tell us who you are and why you need them. No plan or payment required.
  2. We approveOur security team reviews it, usually within one business day.
  3. Sign the NDAA short mutual NDA, signed in your browser. You keep a countersigned copy.
  4. ReadThey open at once, watermarked to you, for 90 days. Renew any time.
Sign in to request access

An account is all we link the NDA to. No plan or payment required.

  • SOC 2 Type II Report

    Report

    Under NDA
  • ISO/IEC 27001:2022

    Certificate

    Under NDA
  • ISO/IEC 42001:2023

    Certificate

    Under NDA
  • Pentest Certificate

    Penetration test

    Under NDA

Controls

How the product protects your research

The controls behind the certifications.

  • Encryption

    • TLS 1.2+ in transit, with HSTS on every Reos domain.
    • AES-256 at rest across the database, object storage and vector indices.
    • Application-level encryption on the most sensitive fields, keys held separately.
  • Access control

    • SSO via SAML, with SCIM provisioning and deprovisioning.
    • Enforceable multi-factor authentication, with role-based access scoped per project and org tag.
    • Least-privilege internal access, reviewed quarterly, with production access logged.
  • Data residency

    • Choose the EU (Frankfurt) or the United States for research data at rest.
    • Database, file storage and vector indices follow that choice.
    • Authentication and organisation registry data stays in the EU.
  • AI governance

    • No provider on our list may train on your research content.
    • AI output is always presented for human review. No automated decisions about individuals.
    • Model and prompt changes go through the ISO 42001 AI lifecycle process.
  • Resilience

    • Point-in-time database recovery, with restores exercised and documented.
    • Backups replicated across providers, encrypted end to end.
    • Business continuity and disaster recovery plans tested annually.
  • Monitoring and response

    • Centralised audit logging of sign-ins, exports and permission changes.
    • Error and performance monitoring, with PII scrubbed before transmission.
    • Documented incident response, with notification inside the windows our DPA commits to.

Subprocessors

Everyone who touches your data, listed.

Every third party that processes personal data for Reos customers, what it does and where. We notify customers 30 days before this list changes.

Version 3 · Effective 29 September 2026 · 20 subprocessors

Infrastructure and hosting

Where the product runs and where customer data rests.

  • CloudflareTerms for Cloudflare (opens in a new tab)

    Purpose
    Hosting, CDN, WAF, object storage (R2), AI Gateway, real-time calls, video transcoding, email delivery
    Data
    All service data, uploaded files
    Processing location
    Regionalised to the customer's data region (EU by default); global edge network
  • TurbopufferTerms for Turbopuffer (opens in a new tab)

    Purpose
    Vector indices for semantic search
    Data
    Embeddings derived from research content
    Processing location
    EU (eu-central-1) or US (us-east-1), matching the customer's data region
  • Amazon Web ServicesTerms for Amazon Web Services (opens in a new tab)

    Purpose
    General cloud hosting and compute, transactional email (SES), media processing, backup storage (S3)
    Data
    Email addresses and names; uploaded media files; backup copies of service data
    Processing location
    EU (eu-central-1) or US (us-east-2), matching the customer's data region

How we use subprocessors

A subprocessor is a third party that processes personal data on behalf of Reos in order to deliver the service. Every subprocessor on this list is bound by a data processing agreement, is assessed before onboarding, and is reviewed at least annually as part of our ISO 27001 supplier management process.

For transfers out of the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on the EU Commission's Standard Contractual Clauses, supplemented by the EU-US Data Privacy Framework where the recipient is certified. Our Transfer Impact Assessment covers these transfers and is re-evaluated at least every six months.

Data residency

Customer research data at rest - database records, uploaded files and vector indices - is stored in the region the customer selects: the EU (Frankfurt) by default, or the United States. Account, authentication and organisation registry data is always stored in the EU (Frankfurt).

AI processing is transient and may occur outside the selected region, as noted per provider above. No research content is retained by an inference provider after the request completes, and no provider on this list is permitted to train models on it.

Changes to this list

We notify customers at least 30 days before a new subprocessor starts processing their personal data, so there is time to object. Notice goes to the email address on the account and appears on this page, with the version and effective date at the top updated in the same change.

If you would like to receive subprocessor change notices at a dedicated address - a security or privacy alias rather than the billing contact - tell us and we will add it.

Questions

The rest of the review

  • Yes, send it over. Most of what a standard questionnaire asks is already on this page, so starting there is faster for both of us.
  • Yes, against a dedicated environment, with scope agreed in writing first. Get in touch and we will set it up.
  • Either. Ours includes the Standard Contractual Clauses and is available on request. If your legal team needs its own paper, we will review it.
  • We log each request, give it a named owner and close it within the statutory deadline. You can also action access, export and deletion from workspace settings.
  • Email security@reos.ai. We acknowledge within one business day and keep you posted through to remediation. We do not take legal action against good-faith research.
  • Flob Inc. holds every agreement, certification and the DPA.

Still reviewing?

Talk to us or read the privacy policy.