Core Security Architecture
Key Security Commitments
Data Isolation & Zero Model Training
Sandboxed Execution: Every agent workflow and container function runs in an isolated runtime environment with memory boundaries enforced at the hypervisor/container level.
No AI Training: Your code, prompts, input payloads, vector indexes, and output logs are never used to train public or foundational models.
Encryption & Secrets Handling
Data in Transit: Secured using TLS 1.3 across all endpoints, control planes, and SDK connections.
Data at Rest: All state databases, vector stores, and backup volumes are encrypted using AES-256.
API Key Vaults: Third-party LLM keys (OpenAI, Anthropic, Mistral) are stored in encrypted key vaults and injected into runtime sandboxes strictly in-memory during execution.
European Data Sovereignty
Primary workloads and database clusters are hosted inside ISO 27001 / SOC 2 certified data centers within the European Union (Germany and Ireland).
Fully compliant with the General Data Protection Regulation (GDPR) and engineered to support compliance under the EU AI Act.
Monitoring, Audit & Incident Response
Logging & Traces: Detailed execution traces, tool call logs, and response metrics enable full auditability of automated agent actions.
24/7 System Telemetry: Continuous monitoring of runtime health, authentication anomalies, and network traffic.
36-Hour Breach Notification: In the event of a confirmed security incident affecting customer data, Sinas will notify impacted users within 36 hours.
Contact Security Team:
Security disclosures or vulnerability reports: support@sinas.co.