Skip to content
00 / SECURITY

FORECAST-GRADE COMPUTER VISION · COMPLIANCE DOSSIER

SOC 2 Type II, ISO 27001, HIPAA, and on-prem/air-gapped — in production at three Fortune 100 manufacturers.

The rest of this page is a procurement-grade dossier. It is written for the security reviewer in your loop, not the marketing reader. Subprocessor list, encryption architecture, pen-test cadence, audit report access, and a direct line to our security team are below.

  • DOCfgcv-sec-v4.2
  • LAST UPDATED2025-03-14
  • REVIEW WINDOWSOC 2: 2024-09 → 2025-03 (continuous)
  • REVIEWER CONTACT[email protected] · +1 (415) 555-0188
01 / CERTIFICATIONS

The four controls a security review opens with.

Each certification is renewed annually with continuous monitoring. Reports, bridge letters, and scope statements are available under NDA through the request form at the bottom of this page.

01 AICPA · TYPE II

SOC 2 Type II

Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity. Scope: FGCV Platform, FGCV-X1 edge runtime, FGCV Eval Suite, supporting infrastructure.

Auditor
Schellman & Co., LLC
Period
2024-09-01 → 2025-08-31 (continuous)
Last report
2025-02-14 (no exceptions)
Score
5.0 / 5.0 — Forrester Wave™ Production ML criterion
Request the report →
02 ISO/IEC 27001:2022

ISO 27001

Information Security Management System covering product engineering, customer data handling, incident response, supplier risk, and physical security at SF / Berlin / Tokyo offices.

Certifier
BSI Group America, Inc.
Certificate
IS 781204 · valid through 2026-11-09
Statement of Applicability
v3.4, 114 Annex A controls assessed
Surveillance
Annual surveillance + triennial re-cert
Request the SoA →
03 HIPAA · 45 CFR §164

HIPAA

FGCV operates as a Business Associate for customers processing PHI in medical imaging workflows. BAA available for both managed-cloud and on-prem deployments.

Safeguards
Administrative, Physical, Technical (45 CFR §164.308–§164.312)
BAA
Counter-signed within 5 business days
Breach window
Notification within 24h of confirmed incident
Audit
Annual third-party HIPAA Security Rule assessment
Request the BAA →
04 DEPLOYMENT MODEL

On-prem & Air-gapped

The same platform ships as a sealed appliance or tarball — no feature fork against managed cloud. Documented deployments at three Fortune 100 manufacturers, including one fully air-gapped site.

Topology
Helm chart · single-binary installer · OVA
Egress
Zero on air-gapped; opt-in telemetry on on-prem
Updates
Signed offline bundles · SHA-256 verified
SLA
Customer-managed; FGCV support under separate MSA
Architecture review →
02 / DEPLOYMENT MODELS

One platform, three runtimes — no security trade-off between them.

The managed cloud, on-prem, and fully air-gapped runtimes share the same SDK, the same SOC 2 Type II controls, the same signed inference runtime, and the same incident response playbook. There is no feature fork and no “secure lite” tier — the binary that ships to an air-gapped Siemens plant in Erlangen is the same one that powers a managed workload for a Series B startup in San Francisco.

  • Managed cloud — multi-tenant on AWS, single-tenant dedicated clusters in US, EU, and APAC. Customer-managed keys (BYOK) via AWS KMS or HashiCorp Vault.
  • On-prem — Helm chart or single-binary installer into the customer's data center. Egress by default closed; opt-in telemetry over a customer-controlled channel.
  • Air-gapped — signed offline bundles, SHA-256 verified at install. No outbound calls. Update packages delivered via customer-approved removable media. Documented at three Fortune 100 manufacturers.
Request architecture review
03 / PRODUCTION GRAVITY

Who is actually running this in regulated environments.

3
Fortune 100 documented on-prem deployments, including one fully air-gapped site
24
of the Fortune 500 in production (Siemens, BMW, Maersk, 7-Eleven named)
19
countries with active production workloads
74
Customer NPS across enterprise accounts (Q1 2025)
BONUS · OPERATIONAL FOOTPRINT 11 annotation languages · 47 full-time CV engineers · 62-person company · 92% gross / 148% net revenue retention FY2024 · 84M Series B (Sequoia, 2024)
04 / SUBPROCESSORS & DATA ARCHITECTURE

Subprocessors, encryption, and data residency.

Copy-pasteable into your vendor risk questionnaire. We notify customers 30 days before any subprocessor change affecting their data.

5.1 Subprocessor list

FGCV engages the following subprocessors to deliver the platform. Customer data is only routed to a subprocessor when the corresponding feature is enabled in the customer's tenant.

SubprocessorPurposeRegionCerts
Amazon Web ServicesManaged cloud compute & storageUS, EU, APACSOC 2 · ISO 27001 · HIPAA
SnowflakeFeature store & analytics warehouseUS, EUSOC 2 · ISO 27001 · HIPAA
DatadogInfrastructure & APM telemetryUS, EUSOC 2 · ISO 27001
Auth0 (Okta)SSO & workforce identityUS, EUSOC 2 · ISO 27001 · HIPAA
CloudflareEdge WAF & DDoSGlobal anycastSOC 2 · ISO 27001
StripeBilling (no model/pixel data)US, EUSOC 2 · ISO 27001 · PCI-DSS L1
ZendeskCustomer support ticketingUS, EUSOC 2 · ISO 27001
NCC GroupAnnual third-party penetration testUK, USCREST · CHECK

5.2 Encryption & data residency

Data is encrypted at rest with AES-256-GCM and in transit with TLS 1.3 (minimum TLS 1.2 for legacy clients). Key management defaults to AWS KMS in the customer's region; customer-managed keys (BYOK) via KMS, HSM, or HashiCorp Vault are available on all plans.

  • At rest. AES-256-GCM. Per-tenant data keys, rotated quarterly. KMS access logged to an immutable WORM audit trail.
  • In transit. TLS 1.3 enforced at the edge; mTLS between platform services; signed inference payloads inside the runtime.
  • Residency. US (us-west-2, us-east-1), EU (eu-central-1, eu-west-1), APAC (ap-northeast-1). Customer-selected region pinned at tenant creation; cross-region replication disabled by default.
  • Keys. Default: FGCV-managed KMS. Available: customer-managed (BYOK), single-tenant HSM, or hold-your-own-key (HYOK) with FGCV never seeing plaintext.
  • Retention. Customer-controlled. Default model artifacts retained while account is active + 30 days; audit logs 13 months hot, 7 years cold, immutable.
  • Deletion. Cryptographic erasure within 24h of termination request; written certificate of deletion issued within 5 business days.

5.3 Access & audit

Customer data access by FGCV personnel requires a documented support ticket, manager approval, time-bound JIT elevation, and produces a tamper-evident audit log entry visible to the customer in real time.

05 / REVIEWER FAQ

Six questions a SOC 2 / HIPAA reviewer asks before scheduling a call.

If your question is not answered here, email [email protected] — a security engineer (not a salesperson) will respond within one business day.

Q.01 Where is customer data stored, and can we pin it to a specific region?

US (us-west-2, us-east-1), EU (eu-central-1, eu-west-1), and APAC (ap-northeast-1) are all available. The region is selected at tenant creation and pinned for the lifetime of the account — cross-region replication is disabled by default and never enabled without a written change request. Air-gapped deployments keep all data on customer infrastructure with zero egress.

Q.02 Do you offer a signed Business Associate Agreement (BAA) for HIPAA workloads?

Yes. Our standard BAA covers managed-cloud and on-prem HIPAA workloads and is counter-signed within five business days. It includes the 24-hour breach notification window, the right to audit, and downstream subprocessor flow-down. A redlined copy is available on request from [email protected].

Q.03 Can we bring our own encryption keys (BYOK) or hold our own keys (HYOK)?

Both are supported. BYOK integrates with AWS KMS, Google Cloud KMS, Azure Key Vault, or HashiCorp Vault in the customer's environment. HYOK is available on the Enterprise tier — FGCV never sees plaintext keys, and key revocation causes immediate cryptographic erasure of all tenant data without a code deploy.

Q.04 What is your penetration-testing cadence, and can we see the executive summary?

NCC Group conducts an annual black-box web/API/network test and a semi-annual internal-network test against the managed cloud. Most recent cycle: 2024-Q4 (no Critical or High findings open). Executive summary is shared under NDA within two business days of a signed request.

Q.05 What is your breach-notification SLA, and who is notified?

Confirmed security incidents affecting customer data trigger notification to the customer's designated security contact within 24 hours, with a written incident report within 72 hours. Regulators and affected data subjects are notified per the customer's instruction and the applicable law (GDPR, HIPAA, state breach laws).

Q.06 How do we access the SOC 2 report, ISO 27001 certificate, and pen-test summary?

Email [email protected] from a corporate domain with your company name and reviewer name. We counter-sign a mutual NDA and deliver the documents via a secure portal within two business days. Reports are refreshed annually and bridge letters are issued for the gap between report cycles.

Still need a document we did not list?

Our security team responds within one business day. No sales routing, no qualification form.