Security at Delphina
Built from the ground up for security, privacy, and compliance.
Customer data is protected, isolated, and encrypted.
Your data will never be used to train shared models.
AICPA SOC 2
Delphina is SOC 2 Type II certified, with an annual audit, continuous controls monitoring, and regular third-party penetration testing. Our audit report is available under NDA.
HIPAA
Delphina is HIPAA compliant, demonstrating our commitment to the rigorous security standards required for handling medical data.
Data Security
You Own Your Data
Delphina does not sell data or use customer data to train shared models.
Hosting Options
Run Delphina either in our secure AWS cloud or deploy inside your VPC so that raw data never leaves your security perimeter.
Encrypted in Transit
All communications between clients and services as well as service and data stores are secured using TLS encryption.
Encrypted at Rest
All data stores are configured with encryption at rest with AES 256-bit encryption using AWS-managed encryption keys.
Single-Tenant Data Plane
Every customer gets a separate, isolated data plane. Raw data is processed on dedicated single-tenant machines.
In Sync with Source
Raw data is only cached, so existing GDPR and CCPA processes work as they are.
Product Security
Authentication & Authorization
Authentication is performed via SAML SSO or OAuth 2.0 with your identity provider. Access to resources is authorized at every level of the stack, including the underlying networking, compute, and storage infrastructure.
Read-Only Warehouse Access
Role-scoped warehouse credentials follow least-privilege access, with no write paths. Delphina respects access controls from each connected integration and enforces RBAC at the namespace level.
Sandboxed Execution
Python and DuckDB run in an isolated Firecracker microVM with no internet access.
Audit Logging
Every prompt, query, and knowledge reference is logged. Structured logs are exportable for review and auditing.
Coding agents belong on laptops.
Sensitive company data doesn’t.
Direct data access
Data & context land on the laptop and stay there.
Hard to track, harder to clean up, and easy to leak.
With Delphina
Data & context stay protected in the governed data plane.
Only answers come back to the browser or coding agent.
Corporate Security
Background Checks
All new team members are required to complete a background check during onboarding, as permitted by local law.
Security Training
All employees are required to complete security training as part of their onboarding process.
Operational Security
Security Testing
We conduct a range of security tests on an ongoing basis, including penetration testing, static and dynamic module scans, and code scanning.
Detection and Response
We employ a range of detection methods throughout our stack, including monitoring administrative endpoints, and have formalized a robust response framework should an incident arise.
Want the full report?
We share our SOC 2 Type II audit and security documentation under NDA.