Trust Center

Secure by design. Trusted by default.

Pallis is built secure from the first line — tenant isolation, encryption, and a full audit trail are part of the architecture, not add-ons bolted onto decades-old software. Your book is protected by how the platform is built, and you'll always know exactly where you stand.

Why Pallis is built to be trusted

01

Isolated by construction

Every tenant is separated at the data layer by row-level security — never co-mingled, never used to train another client's models. Isolation isn't a setting you configure; it's how the platform is built.

02

Honest by default

You always know exactly where you stand. Everything we tell you is verifiable; where a standard is still maturing, we name it plainly and show the timeline — no decoration, no fine print, no surprises six months in.

03

Every decision is auditable

Model versions, data access, and configuration changes are recorded in an immutable, exportable trail — wired in by default, not opt-in. No black boxes.

04

Secrets stay out of the database

API keys and access tokens live in an encrypted secrets vault. Postgres holds only an opaque reference — so a database is never a key store.

How your data is protected

The controls below are live today, enforced at the platform layer — not configured per customer.

Row-level tenant isolation
Every query is scoped to its tenant by construction.
Encrypted in transit & at rest
TLS in transit, AES-256 at rest, encrypted backups.
Immutable audit trail
Append-only, org-scoped, exportable for review.
Secrets vault
Credentials never touch the application database.
Role-based access
Least-privilege defaults, per-org access scoping.
Vetted infrastructure
Built on named providers; dependency scanning.
See the full technical security overview →

The controls auditors check for — already in place

Certification validates security; it doesn't create it. The isolation, encryption, and audit controls a SOC 2 examiner looks for are live in Pallis today — formal attestation is the next milestone, on a defined path.

SOC 2 Type I
Audit prep underway

Security controls implemented; preparing for our first independent examination.

SOC 2 Type II
Targeted 2027

Extends Type I across a full observation window.

ISO/IEC 27001
On the roadmap

An accredited information-security management system.

Need to move now? We complete your security questionnaire and work directly with your team. security@pallis.ai →
You're trusting Pallis with the numbers your business runs on — and we don't take that lightly. Every claim we make, you can verify. Every control we describe is live today. Anything still on the roadmap, we tell you plainly — so you never have to second-guess whether what we told you is true.
The Pallis team
Our promise to you