Alcatraz AI · Trust Center

Alcatraz Ai Trust Center

Trust center

Alcatraz AI maintains a public trust center documenting SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 compliance.

CompanyAccess ControlBiometricsFacial AuthenticationPhysical SecurityIdentityInternet of ThingsArtificial Intelligence
Trust center: https://www.alcatraz.ai/resources/privacy-trust-center

Certifications & Compliance

SOC 2 Type IIISO/IEC 27001ISO/IEC 27017ISO/IEC 27018

Source

Trust Center

alcatraz-ai-trust-center.yml Raw ↑
generated: '2026-08-06'
method: searched
probe: true
probe_note: '0-working/probe-security-programs.py returned trust=none — it checks trust./security.
  subdomains and /trust, /security, /compliance at the apex. Alcatraz AI publishes its
  trust material one level down, at /resources/privacy-trust-center and /resources/security,
  which were then fetched and verified by hand.'
url: https://www.alcatraz.ai/resources/privacy-trust-center
pages:
- name: Privacy & Trust Center
  url: https://www.alcatraz.ai/resources/privacy-trust-center
- name: Security
  url: https://www.alcatraz.ai/resources/security
- name: Responsible AI
  url: https://www.alcatraz.ai/resources/responsible-ai
- name: Availability
  url: https://www.alcatraz.ai/resources/availability
- name: Rock Privacy Policy
  url: https://www.alcatraz.ai/utilities/rock-privacy-policy
certifications:
- SOC 2 Type II
- ISO/IEC 27001
- ISO/IEC 27017
- ISO/IEC 27018
compliance_programs:
- GDPR
- CCPA
- BIPA
controls:
- encryption at rest — AES-256 for facial signatures and system data on the Rock
- encryption in transit — TLS 1.2+
- edge processing — one-way transform of 3D scans into encrypted data blobs that cannot
  be reverted to an image; no raw facial image stored or transmitted
- third-party penetration testing against platform and hardware
- continuous vulnerability scanning of cloud and edge devices
- DTAP (development, testing, acceptance, production) firmware release process
- profiles linked only to an existing badge ID; no name, gender or job title captured
- auto-deletion of inactive users; opted-out users have no facial data captured
gaps:
- No public vulnerability disclosure or bug bounty program; no security.txt (404 on
  every Alcatraz host probed) and no security@ contact published.
- No trust portal with downloadable evidence (no Vanta/Drata/SafeBase-style artifact
  request flow found).
- The SOC 2 Type II claim on the security page is attributed to the underlying AWS
  infrastructure rather than to an Alcatraz-scoped report; no report identifier or
  audit period is published.
- No public status page URL, although the availability page states one is provided
  to customers.
x-evidence:
- url: https://www.alcatraz.ai/resources/security
  http_status: 200
  fetched: '2026-08-06'
  keywords: [soc 2 type ii, iso/iec 27001, iso/iec 27017, iso/iec 27018, aes-256, tls 1.2, penetration test]
- url: https://www.alcatraz.ai/resources/privacy-trust-center
  http_status: 200
  fetched: '2026-08-06'
  keywords: [gdpr, ccpa, bipa, privacy by design]
- url: https://www.alcatraz.ai/.well-known/security.txt
  http_status: 404
  fetched: '2026-08-06'