Security
Blaise security posture, stated plainly.
Blaise is operated by Sekuir Technologies, LLC. It is built as a multi-tenant SaaS platform with tenant isolation, encrypted transport, guarded secret handling, and opt-in AI. We do not claim SOC 2 or ISO certification for Blaise today.
Live Trust Center
Proof, continuously verified
Shareable · token-gated · access logged
MFA
Verified 2 hours ago
Backups
Tested nightly
Evidence
128 artifacts on file
Platform safeguards
How Blaise protects the operating platform.
Tenant isolation
Blaise uses multi-tenant Postgres with row-level security policies to keep organization and client data scoped to authorized users and service paths.
Encryption in transit
Application traffic uses encrypted transport so browser, API, and service communication is protected in transit.
Least-context access
Public pages, auth flows, and app surfaces are separated so unauthenticated users do not reach tenant data paths.
Secrets handling
Connector credentials and service secrets are handled through guarded application paths. Some MVP connector rows may store secrets until hardened vault storage is applied.
AI is opt-in
AI workflows are opt-in and on-demand. Blaise does not train models on your data.
Auditability
Evidence, decisions, approvals, remediation actions, and AI-assisted outputs are designed to stay reviewable for operators and stakeholders.
Honest security posture
What we claim, and what we do not claim.
Blaise helps customers prepare and evidence compliance programs, but Blaise itself is not currently marketing a SOC 2 or ISO 27001 certification claim.
We do claim
RLS-backed tenant isolation, encrypted transport, guarded secrets handling, opt-in AI, and reviewable operating records.
We do not claim
SOC 2 certification, ISO 27001 certification, HITRUST support, or that Blaise issues customer certifications.
AI posture
AI is opt-in and on-demand; we don't train models on your data.
Customer responsibility
Customers still control user access, connector consent, workspace configuration, and which remediation actions are approved.
Custody
What we never hold.
No regulated content
Blaise holds compliance metadata and evidence artifacts — never CUI or PHI content. Upload paths carry a no-regulated-data attestation, and inbound files hold in a review queue until a person approves them.
Keys stay with you
Client backups of self-hosted service data are client-side encrypted before they reach storage; the storage provider never holds the key.
Evidence integrity
How evidence stays honest.
Answers are not proof
Answers never satisfy a control — accepted evidence does. Verification requires a named reviewer who opened the artifact; there is no bulk verify.
Version-stamped signatures
A substantive document change invalidates prior signatures through a dated watermark, and every acknowledgment records who, when, and against which version.
A full custody chain
Every stored-file open and download is written to an access ledger. Evidence exports carry the chain: collected by, verified by, signed at version.
Sub-processors
Who Blaise relies on to operate.
These are the core sub-processors that may process customer data when you use Blaise. Connector integrations (e.g. Microsoft 365, Defender, Google) read from systems you already own and control. They are your systems, not Blaise sub-processors. AI providers are used only when you opt into an AI feature, and Blaise does not train models on your data. Contact us for the current list for contracting.
Supabase
Database, authentication, file storage, and edge compute
Vercel
Application hosting and content delivery (CDN)
Anthropic
AI features (opt-in, on-demand), no training on your data
OpenAI
Embeddings and transcription for select AI features (opt-in)
Resend / Postmark
Transactional email delivery
Stripe
Billing and payment processing
Browserless
Server-side PDF rendering (when report export is enabled)
OpenSign
E-signature for agreements (when used)
Related pages
Continue the trust review.
Build the stakeholder story before the meeting starts.
See how Blaise turns posture, risk, evidence, vendors, roadmap, and decisions into a board-ready operating rhythm.
