Platform & Infrastructure Security

Modern, secure, and scalable cloud foundations.

Zero-Trust Architecture

No user or service is trusted by default. Every request is independently authenticated and authorized. Internal traffic is protected via mTLS.

Encryption at Rest & In Transit

TLS 1.3 for data in transit, AES-256 for data at rest across databases, object storage, and caches.

Multi-Tenant Isolation

Strict tenant isolation at the application layer. Optional dedicated VPC deployments for enterprises.

Secure Cloud Infrastructure

Hosted on AWS with state-of-the-art physical security, redundancy, and monitoring.

Application & Data Security

Security built into the SDLC and product controls.

Secure SDLC

Security training, code reviews, SAST/DAST, and dependency scanning are part of our engineering process.

Granular RBAC

Role-Based Access Control enables least-privilege access and precise permissioning.

Authentication & SSO

Strong passwords and MFA for all users. Enterprise SSO via SAML 2.0/OIDC with providers like Okta and Azure AD.

Secure AI Handling

RAG with permission pre-filtering prevents data leakage. PII/PHI identification and redaction features built-in.

Organizational Security & Compliance

Policy, process, and validation.

Penetration Testing

Regular third-party penetration tests help us proactively identify and remediate vulnerabilities.

Vulnerability Management

Formal program with SLAs for critical issues to ensure timely remediation.

Incident Response

Comprehensive IR plan and team to investigate and respond to potential security events.

Compliance Roadmap

Aligning with SOC 2 Type II and ISO 27001. Building controls for external validation.

Your Role in Security

  • Implement strong passwords and enable MFA for all users.
  • Use RBAC to enforce least-privilege access.
  • Regularly review user access and audit logs.

Reporting a Security Vulnerability

If you believe you have discovered a security vulnerability, please report it to security@projectpath.ai. We are committed to prompt, responsible disclosure and resolution.