Alcatraz AI · Trust Center
Alcatraz Ai Trust Center
Trust center
Alcatraz AI maintains a public trust center documenting SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 compliance.
CompanyAccess ControlBiometricsFacial AuthenticationPhysical SecurityIdentityIoTArtificial Intelligence
Trust center: https://www.alcatraz.ai/resources/privacy-trust-center
Certifications & Compliance
SOC 2 Type IIISO/IEC 27001ISO/IEC 27017ISO/IEC 27018
Source
Trust Center
generated: '2026-08-06'
method: searched
probe: true
probe_note: '0-working/probe-security-programs.py returned trust=none — it checks trust./security.
subdomains and /trust, /security, /compliance at the apex. Alcatraz AI publishes its
trust material one level down, at /resources/privacy-trust-center and /resources/security,
which were then fetched and verified by hand.'
url: https://www.alcatraz.ai/resources/privacy-trust-center
pages:
- name: Privacy & Trust Center
url: https://www.alcatraz.ai/resources/privacy-trust-center
- name: Security
url: https://www.alcatraz.ai/resources/security
- name: Responsible AI
url: https://www.alcatraz.ai/resources/responsible-ai
- name: Availability
url: https://www.alcatraz.ai/resources/availability
- name: Rock Privacy Policy
url: https://www.alcatraz.ai/utilities/rock-privacy-policy
certifications:
- SOC 2 Type II
- ISO/IEC 27001
- ISO/IEC 27017
- ISO/IEC 27018
compliance_programs:
- GDPR
- CCPA
- BIPA
controls:
- encryption at rest — AES-256 for facial signatures and system data on the Rock
- encryption in transit — TLS 1.2+
- edge processing — one-way transform of 3D scans into encrypted data blobs that cannot
be reverted to an image; no raw facial image stored or transmitted
- third-party penetration testing against platform and hardware
- continuous vulnerability scanning of cloud and edge devices
- DTAP (development, testing, acceptance, production) firmware release process
- profiles linked only to an existing badge ID; no name, gender or job title captured
- auto-deletion of inactive users; opted-out users have no facial data captured
gaps:
- No public vulnerability disclosure or bug bounty program; no security.txt (404 on
every Alcatraz host probed) and no security@ contact published.
- No trust portal with downloadable evidence (no Vanta/Drata/SafeBase-style artifact
request flow found).
- The SOC 2 Type II claim on the security page is attributed to the underlying AWS
infrastructure rather than to an Alcatraz-scoped report; no report identifier or
audit period is published.
- No public status page URL, although the availability page states one is provided
to customers.
x-evidence:
- url: https://www.alcatraz.ai/resources/security
http_status: 200
fetched: '2026-08-06'
keywords: [soc 2 type ii, iso/iec 27001, iso/iec 27017, iso/iec 27018, aes-256, tls 1.2, penetration test]
- url: https://www.alcatraz.ai/resources/privacy-trust-center
http_status: 200
fetched: '2026-08-06'
keywords: [gdpr, ccpa, bipa, privacy by design]
- url: https://www.alcatraz.ai/.well-known/security.txt
http_status: 404
fetched: '2026-08-06'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/alcatraz-ai-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.