Security
Blaise security posture, stated plainly.
Blaise is operated by Sekuir Technologies, LLC. It is built as a multi-tenant SaaS platform with tenant isolation, encrypted transport, guarded secret handling, and opt-in AI. We do not claim SOC 2 or ISO certification for Blaise today.
Live Trust Center
Proof, continuously verified
Shareable · token-gated · access logged
MFA
Verified 2 hours ago
Backups
Tested nightly
Evidence
128 artifacts on file
Platform safeguards
How Blaise protects the operating platform.
Tenant isolation
Blaise uses multi-tenant Postgres with row-level security policies to keep organization and client data scoped to authorized users and service paths.
Encryption in transit
Application traffic uses encrypted transport so browser, API, and service communication is protected in transit.
Least-context access
Public pages, auth flows, and app surfaces are separated so unauthenticated users do not reach tenant data paths.
Secrets handling
Connector credentials and service secrets are handled through guarded application paths. Some MVP connector rows may store secrets until hardened vault storage is applied.
AI is opt-in
AI workflows are opt-in and on-demand. Blaise does not train models on your data.
Auditability
Evidence, decisions, approvals, remediation actions, and AI-assisted outputs are designed to stay reviewable for operators and stakeholders.
Honest security posture
What we claim, and what we do not claim.
Blaise helps customers prepare and evidence compliance programs, but Blaise itself is not currently marketing a SOC 2 or ISO 27001 certification claim.
We do claim
RLS-backed tenant isolation, encrypted transport, guarded secrets handling, opt-in AI, and reviewable operating records.
We do not claim
SOC 2 certification, ISO 27001 certification, HITRUST support, or that Blaise issues customer certifications.
AI posture
AI is opt-in and on-demand; we don't train models on your data.
Customer responsibility
Customers still control user access, connector consent, workspace configuration, and which remediation actions are approved.
Sub-processors
Who Blaise relies on to operate.
These are the core sub-processors that may process customer data when you use Blaise. Connector integrations (e.g. Microsoft 365, Defender, Google) read from systems you already own and control. They are your systems, not Blaise sub-processors. AI providers are used only when you opt into an AI feature, and Blaise does not train models on your data. Contact us for the current list for contracting.
Supabase
Database, authentication, file storage, and edge compute
Vercel
Application hosting and content delivery (CDN)
Anthropic
AI features (opt-in, on-demand), no training on your data
OpenAI
Embeddings and transcription for select AI features (opt-in)
Resend / Postmark
Transactional email delivery
Stripe
Billing and payment processing
Browserless
Server-side PDF rendering (when report export is enabled)
OpenSign
E-signature for agreements (when used)
Related pages
Continue the trust review.
Build the stakeholder story before the meeting starts.
See how Blaise turns posture, risk, evidence, vendors, roadmap, and decisions into a board-ready operating rhythm.
