Trust Center
Security at Wand
Security is foundational to everything we build. This page outlines our security practices, infrastructure controls, and how to reach our security and privacy teams.
Compliance
We are completing our first SOC 2 Type II examination (2026 cycle), covering our SaaS platform. A report will be available to customers under NDA once the examination concludes. To request it, contact security@wand.ai.
SOC 2 Type II
Examination in progress — 2026 cycleSaaS platform. Report available to customers under NDA once the examination concludes.
GDPR
ReadyEU/EEA customer personal data processing.
Security Controls
Wand’s production infrastructure runs on a major public cloud provider, with a primary region in the United States and additional regions across Europe, Asia-Pacific, and the Americas.
Infrastructure & Cloud Security
6 controls
- ✓Private architecture — production compute runs in a private configuration with no direct public administrative access from the internet
- ✓Network segmentation — segmented network topology with least-privilege traffic rules enforced between layers; firewall rules are reviewed at least annually
- ✓Encryption at rest — strong industry-standard encryption is applied to stored data across our storage and database services
- ✓Encryption in transit — modern TLS is enforced on external endpoints
- ✓Vulnerability scanning — continuous vulnerability scanning and alerting across our cloud workloads
- ✓DDoS protection — network and edge-level protections against denial-of-service attacks
Access Control
6 controls
- ✓Identity — single sign-on with multi-factor authentication for personnel
- ✓Least privilege — role-based access control applied across systems, with access granted on a least-privilege basis
- ✓Privileged access — administrative access to production is restricted to controlled, audited pathways
- ✓Secrets management — credentials are managed through dedicated secrets management; we do not permit plaintext secrets in source code repositories
- ✓Access reviews — we conduct periodic access reviews, at least quarterly, across in-scope systems
- ✓Offboarding — our policy is to revoke access upon role change or termination
Application Security
4 controls
- ✓Secure development — security considerations are integrated into our development lifecycle, and our policy requires peer code review for changes
- ✓CI/CD pipeline — changes flow through an automated build and deployment pipeline
- ✓Container security — container images are scanned before deployment, with admission controls applied
- ✓Dependency management — automated dependency and vulnerability scanning
Monitoring & Incident Response
4 controls
- ✓Logging & monitoring — centralized logging and monitoring with alerting
- ✓Threat detection — security monitoring with anomaly detection
- ✓Incident response — we maintain a documented incident response plan
- ✓Security incidents — in the event of a security incident affecting personal data, we will notify affected parties and the appropriate authorities as required by applicable law
People Security
1 control
- ✓Security awareness training — personnel complete security awareness training
Business Continuity & Disaster Recovery
3 controls
- ✓Resilient deployment — production is deployed across multiple availability zones
- ✓Backups — regular backups of critical systems and data, with defined retention
- ✓Disaster recovery — a secondary region is configured to support recovery
Vendor & Third-Party Risk
3 controls
- ✓Sub-processor review — cloud and SaaS sub-processors are reviewed at least annually
- ✓Data Processing Addenda — we put data processing terms in place with sub-processors that handle personal data
- ✓Cybersecurity insurance — Wand maintains a cybersecurity insurance policy
- ✓Vendor access — third-party access to personal data is limited to what is necessary
Data Security & Privacy
Our privacy practices, including how we handle personal data, are described in our Privacy Policy.
Data classification
Data is classified with corresponding handling requirements.
Data minimization
We aim to limit the personal data we store to what is necessary.
Data retention
Personal data is retained only as long as necessary for the purposes described in our Privacy Policy.
Data deletion
We honor data subject and deletion requests as required by applicable law; submit requests to privacy-dpo@wand.ai.
International transfers
Where personal data is transferred across borders, we use appropriate safeguards.
Sub-processors
We maintain a sub-processor inventory, available on request.
Responsible Disclosure
If you discover a security vulnerability in Wand’s products or infrastructure, please report it to security@wand.ai. We aim to acknowledge reports promptly and do not pursue legal action against researchers acting in good faith.
Report a VulnerabilityPrivacy & Data Requests
To exercise your data rights or request deletion of your personal data, contact privacy-dpo@wand.ai. We handle requests as required by applicable law. For more on how we process personal data, see our Privacy Policy.
Submit a RequestContact Us
Reach the right team directly for security, privacy, and compliance matters.
Wand Synthesis AI Inc., 838 Walker Road, Dover, DE 19904 | This page is reviewed and updated at least annually. | Full Privacy Policy