Skip to content

Trust Center

Security at Wand

Security is foundational to everything we build. This page outlines our security practices, infrastructure controls, and how to reach our security and privacy teams.

Compliance

We are completing our first SOC 2 Type II examination (2026 cycle), covering our SaaS platform. A report will be available to customers under NDA once the examination concludes. To request it, contact security@wand.ai.

SOC 2

SOC 2 Type II

Examination in progress — 2026 cycle

SaaS platform. Report available to customers under NDA once the examination concludes.

GDPR

GDPR

Ready

EU/EEA customer personal data processing.

Security Controls

Wand’s production infrastructure runs on a major public cloud provider, with a primary region in the United States and additional regions across Europe, Asia-Pacific, and the Americas.

Infrastructure & Cloud Security

6 controls

  • Private architecture — production compute runs in a private configuration with no direct public administrative access from the internet
  • Network segmentation — segmented network topology with least-privilege traffic rules enforced between layers; firewall rules are reviewed at least annually
  • Encryption at rest — strong industry-standard encryption is applied to stored data across our storage and database services
  • Encryption in transit — modern TLS is enforced on external endpoints
  • Vulnerability scanning — continuous vulnerability scanning and alerting across our cloud workloads
  • DDoS protection — network and edge-level protections against denial-of-service attacks

Access Control

6 controls

  • Identity — single sign-on with multi-factor authentication for personnel
  • Least privilege — role-based access control applied across systems, with access granted on a least-privilege basis
  • Privileged access — administrative access to production is restricted to controlled, audited pathways
  • Secrets management — credentials are managed through dedicated secrets management; we do not permit plaintext secrets in source code repositories
  • Access reviews — we conduct periodic access reviews, at least quarterly, across in-scope systems
  • Offboarding — our policy is to revoke access upon role change or termination

Application Security

4 controls

  • Secure development — security considerations are integrated into our development lifecycle, and our policy requires peer code review for changes
  • CI/CD pipeline — changes flow through an automated build and deployment pipeline
  • Container security — container images are scanned before deployment, with admission controls applied
  • Dependency management — automated dependency and vulnerability scanning

Monitoring & Incident Response

4 controls

  • Logging & monitoring — centralized logging and monitoring with alerting
  • Threat detection — security monitoring with anomaly detection
  • Incident response — we maintain a documented incident response plan
  • Security incidents — in the event of a security incident affecting personal data, we will notify affected parties and the appropriate authorities as required by applicable law

People Security

1 control

  • Security awareness training — personnel complete security awareness training

Business Continuity & Disaster Recovery

3 controls

  • Resilient deployment — production is deployed across multiple availability zones
  • Backups — regular backups of critical systems and data, with defined retention
  • Disaster recovery — a secondary region is configured to support recovery

Vendor & Third-Party Risk

3 controls

  • Sub-processor review — cloud and SaaS sub-processors are reviewed at least annually
  • Data Processing Addenda — we put data processing terms in place with sub-processors that handle personal data
  • Cybersecurity insurance — Wand maintains a cybersecurity insurance policy
  • Vendor access — third-party access to personal data is limited to what is necessary

Data Security & Privacy

Our privacy practices, including how we handle personal data, are described in our Privacy Policy.

Data classification

Data is classified with corresponding handling requirements.

Data minimization

We aim to limit the personal data we store to what is necessary.

Data retention

Personal data is retained only as long as necessary for the purposes described in our Privacy Policy.

Data deletion

We honor data subject and deletion requests as required by applicable law; submit requests to privacy-dpo@wand.ai.

International transfers

Where personal data is transferred across borders, we use appropriate safeguards.

Sub-processors

We maintain a sub-processor inventory, available on request.

Responsible Disclosure

If you discover a security vulnerability in Wand’s products or infrastructure, please report it to security@wand.ai. We aim to acknowledge reports promptly and do not pursue legal action against researchers acting in good faith.

Report a Vulnerability

Privacy & Data Requests

To exercise your data rights or request deletion of your personal data, contact privacy-dpo@wand.ai. We handle requests as required by applicable law. For more on how we process personal data, see our Privacy Policy.

Submit a Request

Contact Us

Reach the right team directly for security, privacy, and compliance matters.

General security inquiries & SOC 2 report requests (NDA) security@wand.ai
Vulnerability / responsible disclosure security@wand.ai
Ethics & compliance concerns ethics@wand.ai
Privacy & data subject requests privacy-dpo@wand.ai

Wand Synthesis AI Inc., 838 Walker Road, Dover, DE 19904  |  This page is reviewed and updated at least annually.  |  Full Privacy Policy