Legal

Security

Last updated: [Month] 2026

1. Overview

Security is core to how Augle operates, given the evidentiary and research use cases our Service supports. This page summarizes the practices we follow to protect your data and the integrity of the Service. It is a high-level summary, not an exhaustive technical specification, and will be updated as our program matures.

2. Infrastructure & hosting

Augle's infrastructure runs on established cloud providers with independently audited data center controls. Production environments are logically isolated from development and staging environments, and infrastructure changes go through a review process before deployment.

3. Encryption

Data is encrypted in transit using TLS 1.2 or higher, and at rest using industry-standard encryption (such as AES-256). Access to encryption keys is restricted to authorized systems and personnel, and key management follows the practices of our infrastructure provider.

4. Access controls

Internal access to production systems and user data is limited to personnel who require it to operate the Service, governed by the principle of least privilege. Access to sensitive systems requires multi-factor authentication, and access grants are periodically reviewed and revoked promptly upon role change or offboarding. Access is logged for audit purposes.

5. Data classification

We classify data by sensitivity (for example, public, internal, confidential, and restricted) and apply handling and access controls appropriate to each classification. Session content and personal information are treated as confidential or restricted.

6. Application security

We follow secure development practices, including code review prior to deployment, dependency and vulnerability scanning, and periodic security testing. [Details on penetration testing cadence and any third-party security audits will be published here once established.]

7. Vendor risk management

Before engaging infrastructure, AI model, or other sub-processor vendors, we review their security and privacy practices, and require contractual data-protection commitments consistent with this page and our Privacy Policy.

8. Backups & disaster recovery

We maintain regular backups of critical data and a disaster recovery process designed to restore Service availability in the event of an outage. [Specific recovery time and recovery point objectives will be published here once finalized.]

9. Physical security

Augle does not operate its own data centers; physical security for infrastructure is provided by our cloud hosting providers, who maintain independently audited physical access controls.

10. Personnel & training

Personnel with access to production systems or user data undergo background checks where legally permitted, and receive security and confidentiality training appropriate to their role. Access is granted only as needed for their function.

11. Guardian & source verification

Alongside infrastructure security, Augle's Guardian system performs independent integrity checks on the evidence used within a deliberation session — verifying citations and flagging issues before a Finding is finalized. This is a product-integrity feature distinct from, and in addition to, the infrastructure security measures described on this page.

12. Responsible disclosure

If you believe you've found a security vulnerability in the Service, please report it to security@augle.com. Include enough detail for us to reproduce the issue. We ask that you:

We will acknowledge good-faith reports and will not pursue legal action against researchers who comply with this policy. [A formal safe-harbor statement and, if applicable, a bug-bounty program with reward tiers will be finalized and published here.]

13. Incident response

Augle maintains an incident response process for identifying, containing, eradicating, and recovering from security incidents, including a defined escalation path and post-incident review. Where an incident affects user data, we will notify affected users and relevant authorities as required by applicable law, without undue delay.

14. Compliance roadmap

[Details on SOC 2 Type II, ISO 27001, or other compliance certifications, if and when pursued, will be published here as they are achieved.]

15. Contact us

Security questions or vulnerability reports can be directed to security@augle.com.