Security at Topiq

Your email, calendar and meetings are some of your most sensitive data. We treat them that way.

This page summarizes how Topiq protects customer data: how it is isolated, encrypted, accessed, monitored and recovered, and which providers process it. If you need more detail, we will complete your organization's security questionnaire or walk your team through our controls on a call.

Security contact: [email protected]

SOC 2 Type II

Audit being scheduled

Controls designed against the SOC 2 Trust Services Criteria.

Penetration testing

Annual, third party

Attestation letter available on request.

Security breaches

None to date

Customers notified within 72 hours of a confirmed breach.

Customer data used to train AI

Never

Pre-trained models only, with zero data retention agreements where available.

Compliance & assurance

Our controls are designed against recognized frameworks today, and we are working toward independent attestation.

SOC 2 Type II

In progress

We are scheduling our SOC 2 Type II audit with an independent audit firm. Our controls already follow the SOC 2 Trust Services Criteria. A Type II audit tests whether those controls operate effectively over a sustained observation period, not just at a single point in time. We will update this page as the audit progresses.

Independent penetration testing

Annual

Third-party security firms test our application and network perimeter at least once a year. The assessments also review security best practices more broadly. We triage findings by severity and remediate them. A penetration test attestation letter is available on request.

Framework alignment

Our Information Security Program follows the SOC 2 Trust Services Criteria, ISO 27001 Annex A and the NIST Cybersecurity Framework. We are not certified against ISO 27001; we use it, alongside the other frameworks, to design and measure our controls.

Security ownership

Our CTO owns security. That covers architecture review, access policy, incident response and vendor risk. A dedicated information security engineer, engaged part time, provides ongoing review and validation of our systems. Our infrastructure runs entirely on AWS, so it also inherits AWS's SOC 2 Type II and ISO 27001 certified physical and infrastructure controls.

How we protect your data

A summary of the controls behind the platform.

Cloud infrastructure & network

  • Hosted entirely on AWS (EKS and RDS) in private subnets. No server or database is publicly reachable.
  • All inbound traffic passes through AWS WAF and an Nginx ingress layer.
  • Service-to-service traffic is encrypted and authenticated with mutual TLS (Linkerd).
  • Security groups permit only the ports and sources each service needs.

Encryption & secrets

  • TLS on every connection. Non-TLS connections are rejected.
  • Databases, object storage and backups are encrypted at rest with AWS KMS-managed keys.
  • OAuth tokens are stored in encrypted fields. Internal secrets live in Doppler and are injected at runtime, never stored in code.
  • Cryptographic operations use constant-time implementations and secure random number generators.

Tenant isolation & access

  • Each customer workspace has its own database schema, and every query is scoped to that workspace.
  • Files are stored under non-guessable UUID identifiers and served only through authenticated requests.
  • Role-based access is enforced server-side at the route, middleware, controller and query layers. If a check fails, the request is denied.
  • Only approved engineers can reach customer data, with temporary access granted only to troubleshoot an issue.

Authentication

  • Customers sign in with SSO only, through Google or Microsoft Entra ID (OIDC), so we never store user passwords.
  • Every employee account requires MFA, using hardware security keys (FIDO2) or TOTP. SMS is not permitted.
  • Sessions are invalidated on logout, and sensitive actions require re-verification.
  • No shared or default accounts exist anywhere in the application or infrastructure.

Secure development

  • Every change requires peer review. Nobody commits directly to protected branches.
  • CodeQL static analysis, secret scanning and Dependabot run automatically on every change.
  • Merges are blocked automatically on high-severity findings, and engineers cannot bypass them.
  • We deploy only through automated CI/CD, and production artifacts are code-signed.

Monitoring & incident response

  • CloudTrail, CloudWatch, VPC Flow Logs, RDS and S3 access logs, plus application audit logs.
  • Automated agents analyze logs continuously for anomalies and escalate alerts to senior engineers.
  • We follow a documented incident response plan with defined severities. The most severe incidents (P1) get a response within 1 hour.
  • Credentials, tokens and personal data are never written to logs.

Backup & resilience

  • The production database runs Multi-AZ, with automatic failover to a standby in a separate availability zone.
  • Automated daily backups are encrypted with KMS and kept for 7 days.
  • Deletion protection guards against accidental data loss.
  • Critical and high-severity patches get expedited deployment.

People

  • All personnel, including contractors, sign confidentiality agreements and our Acceptable Use Policy.
  • Everyone completes security onboarding with our CTO. Engineers also complete secure-coding training.
  • All credentials are managed in 1Password, and SSH keys never sit on disk as plaintext.

Endpoints

  • Company-issued macOS devices only. Personal devices (BYOD) are not allowed for employees.
  • Every device has full-disk encryption, a firewall, auto-lock and automatic security updates enabled.
  • Lost or stolen devices can be locked or wiped remotely.

Privacy & responsible AI

AI is central to Topiq. Here is how we keep it from becoming a risk to your data.

Your data stays yours

  • You own and control your data. We process it only to provide the service.
  • We do not sell personal information, and we never examine customer data without your express permission.
  • We honor access and deletion requests, and deletions extend to the subprocessors we control.
  • Data is classified into four protection levels (Public, Internal, Confidential, Restricted), each with defined handling requirements.
Read our Privacy Policy

AI governance

  • We use only pre-trained models from established providers (OpenAI, Deepgram). We do no training or fine-tuning on customer data.
  • Each request is stateless and contains only the data it needs. Prompts are not logged.
  • We hold zero data retention agreements with AI providers where available.
  • A formal AI Governance Policy and prompt evaluations guard output quality. AI assists users and never makes autonomous decisions.

Subprocessors

We keep our vendor footprint small. Our CTO approves every provider that touches customer data, after a security review.

Provider Purpose Data handling
Amazon Web Services Hosting, database, storage and compute Processes and stores customer data
Google Email and calendar integration (Google Workspace APIs) Processes customer data
Microsoft Email and calendar integration (Microsoft Graph APIs) Processes customer data
OpenAI AI features: summarization, analysis, smart replies Processes customer data; zero data retention on API requests
Deepgram Meeting transcription (speech-to-text) Processes customer data; audio not retained after processing
Slack Messaging integration Processes customer data
Zoom Meeting integration Data is received from Zoom only; no customer data is sent to it

AI processing currently takes place in the United States. All data sent to subprocessors is encrypted in transit.

Security documentation

Our Privacy Policy, Terms of Service and DPA are public. The other documents are available to customers and prospects on request; some may require a mutual NDA.

Penetration test attestation

Summary letter from our most recent third-party test

On request

Information Security Program overview

Governance, risk management and control domains

On request

Security Incident Response Plan

Severity levels, roles and customer notification

On request

Data Classification Policy

Protection levels and the data classification matrix

On request

AI Governance Policy

Provider selection, data handling and responsible use

On request

Your security questionnaire

We are glad to complete your organization's questionnaire

On request

SOC 2 Type II report

Will be available after the audit is complete

Coming
Public

Terms of Service

gettopiq.ai/terms

Public

Data Processing Addendum (DPA)

gettopiq.ai/dpa

Public

Have a question we haven't answered?

Contact us to request documents, report a security concern or set up a call with our CTO. Every customer also has a dedicated account representative.

Email [email protected]

Contact security

Last updated October 2026. This page summarizes our security practices and does not modify any agreement between Topiq and its customers.