cited.ai
Sign in

Security & trust

Customers share sensitive catalogs and shopper data. Formal certifications (SOC2, ISO, etc.) are on the roadmap—the points below describe how we build today's stack.

Infrastructure
Production workloads run on Google Cloud with region-aware deployment planning for customers who require data locality in GCC geographies whenever Google provides suitable SKUs.
Encryption & transport
TLS envelopes traffic to/from browsers plus service-to-service calls; secrets reside in encrypted stores.
Access controls
Role-aware admin consoles, audited API keys, SSO roadmap items, segregation between pilot tenants—documented onboarding for every operator.
Vulnerability response
Report suspected issues responsibly to founders@cited.ai—we investigate, patch, disclose proportionally to impacted customers.

Questions about PDPL-aligned processing, DPIAs, SOC2 artefacts, or security reviews?

Contact us