Alcatraz AI · Trust Center

Alcatraz Ai Trust Center

Trust center

Alcatraz AI maintains a public trust center documenting SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 compliance.

CompanyAccess ControlBiometricsFacial AuthenticationPhysical SecurityIdentityInternet of ThingsArtificial Intelligence
Trust center: https://www.alcatraz.ai/resources/privacy-trust-center

Certifications & Compliance

SOC 2 Type IIISO/IEC 27001ISO/IEC 27017ISO/IEC 27018

Source

Trust Center

alcatraz-ai-trust-center.yml Raw ↑
generated: '2026-08-06'
method: searched
probe: true
probe_note: '0-working/probe-security-programs.py returned trust=none — it checks trust./security.
  subdomains and /trust, /security, /compliance at the apex. Alcatraz AI publishes its
  trust material one level down, at /resources/privacy-trust-center and /resources/security,
  which were then fetched and verified by hand.'
url: https://www.alcatraz.ai/resources/privacy-trust-center
pages:
- name: Privacy & Trust Center
  url: https://www.alcatraz.ai/resources/privacy-trust-center
- name: Security
  url: https://www.alcatraz.ai/resources/security
- name: Responsible AI
  url: https://www.alcatraz.ai/resources/responsible-ai
- name: Availability
  url: https://www.alcatraz.ai/resources/availability
- name: Rock Privacy Policy
  url: https://www.alcatraz.ai/utilities/rock-privacy-policy
certifications:
- SOC 2 Type II
- ISO/IEC 27001
- ISO/IEC 27017
- ISO/IEC 27018
compliance_programs:
- GDPR
- CCPA
- BIPA
controls:
- encryption at rest — AES-256 for facial signatures and system data on the Rock
- encryption in transit — TLS 1.2+
- edge processing — one-way transform of 3D scans into encrypted data blobs that cannot
  be reverted to an image; no raw facial image stored or transmitted
- third-party penetration testing against platform and hardware
- continuous vulnerability scanning of cloud and edge devices
- DTAP (development, testing, acceptance, production) firmware release process
- profiles linked only to an existing badge ID; no name, gender or job title captured
- auto-deletion of inactive users; opted-out users have no facial data captured
gaps:
- No public vulnerability disclosure or bug bounty program; no security.txt (404 on
  every Alcatraz host probed) and no security@ contact published.
- No trust portal with downloadable evidence (no Vanta/Drata/SafeBase-style artifact
  request flow found).
- The SOC 2 Type II claim on the security page is attributed to the underlying AWS
  infrastructure rather than to an Alcatraz-scoped report; no report identifier or
  audit period is published.
- No public status page URL, although the availability page states one is provided
  to customers.
x-evidence:
- url: https://www.alcatraz.ai/resources/security
  http_status: 200
  fetched: '2026-08-06'
  keywords: [soc 2 type ii, iso/iec 27001, iso/iec 27017, iso/iec 27018, aes-256, tls 1.2, penetration test]
- url: https://www.alcatraz.ai/resources/privacy-trust-center
  http_status: 200
  fetched: '2026-08-06'
  keywords: [gdpr, ccpa, bipa, privacy by design]
- url: https://www.alcatraz.ai/.well-known/security.txt
  http_status: 404
  fetched: '2026-08-06'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/alcatraz-ai-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.