Security & Trust
CETRAI security: US-only hosting, AES-256 encryption, single-tenant isolation, SOC 2 Type II in progress, Cyber Essentials Plus and no training on your data.
CETRAI's trust center covers platform hosting, encryption, access management, data handling, subprocessors, and incident reporting.
- Platform & hosting
- Access & authentication
- Data handling
- Subprocessors & integrations
- Shared responsibility
- Incident & vulnerability reporting
CETRAI is built for high-volume, regulated environments where accuracy, accessibility, and data security are non-negotiable. It is developed and operated by Cetrix Technologies LLC (CETDIGIT), a US company serving government, education, and enterprise clients.
Certifications & Assessments
- Cyber Essentials Plus certified.
- SOC 2 Type II examination in progress.
- HECVAT Light completed and available to institutions that require it.
- Annual third-party penetration testing, with results available to clients.
- Continuous automated vulnerability scanning.
Data Protection
- AES-256 encryption at rest; TLS 1.2+ in transit.
- US-only data hosting (Azure or AWS, US regions).
- Logically isolated single-tenant architecture per client.
- Automatic PII detection and masking, configurable per client policy.
- Configurable data retention — 7, 30, 90, or 365 days, or purge at end of session.
- Zero-retention mode: conversation content can be set never to be stored — not archived, not analyzed, not recoverable.
- Clear on close: the visitor-side transcript can optionally be wiped the moment the chat window closes.
Your Data Stays Yours
- All logs, transcripts, training data, and configurations are the sole property of the client.
- Zero use of client data for AI model training. No client data is shared with third parties.
- Notification of any confirmed security incident affecting client data.
Reliable by Design
- 99.9% uptime SLA with geo-redundant infrastructure.
- Disaster recovery: recovery point objective (RPO) of 4 hours and recovery time objective (RTO) of 8 hours.
- Graceful degradation: if a model provider is impaired, the routing layer fails over rather than failing the conversation.
- Every AI answer is grounded in your approved content with mandatory source citations — no open-web answers, no made-up responses.
- Role-based access control, approval workflows, and full audit logging for content and configuration changes.
- Access security: SSO via Microsoft Entra ID (Azure AD), Okta, and other SAML/OIDC providers, with multi-factor authentication.
Public-sector procurement
CETDIGIT holds a position on the State of Montana Master AI Products and Services Contract (RFP SPB-RFP-2026-0608GW), awarded through competitive statewide procurement and running through June 30, 2028. CETRAI is the platform offered to Montana agencies under that contract, which is also available for cooperative purchasing under 18-4-401, MCA. CETDIGIT (Cetrix Technologies LLC) holds TIPS Contract 220105, Technology Solutions, Products and Services. TIPS members in all 50 states, DC, Puerto Rico and the US Virgin Islands can purchase CETRAI through it with a purchase order referencing the contract number, without running their own solicitation.
Compliance Support
Deployments are configured to align with GDPR, FERPA, and HIPAA-ready operation with an executed Business Associate Agreement. Compliance ownership remains with the agency; CETDIGIT configures and evidences the technical controls. CETRAI deployments can also be configured to support Section 508 / ADA (WCAG 2.1 AA) requirements — a VPAT / Accessibility Conformance Report is available on request for submission with a bid. Certificates of insurance, W-9, and security documentation are available to evaluators on request.
Questions
Contact us at info@cetdigit.com.
Related policies
Other CETRAI legal, privacy, and security documents.