Trust Center
State0 is built on a foundation of responsible AI, rigorous data privacy, and enterprise-grade security. This page documents our commitments, certifications, and the controls we apply to every deployment.
Last reviewed: May 2026 · Questions? security@state0.io
SOC 2 Type II Compliant
Audited by an independent third-party CPA firm. Controls covering Security, Availability, and Confidentiality are verified against the AICPA Trust Services Criteria on a continuous basis.
ISO 42001 Ready — AI Management
Our AI governance framework aligns with ISO/IEC 42001:2023 requirements for AI Management Systems, covering risk assessment, transparency obligations, and human oversight controls.
Compliance reports and attestation letters are available to enterprise customers under NDA. Request access
AI features inside State0 — from the AI Architect to the AI Gateway — are designed to amplify human judgement, not replace it. Every model interaction is logged, attributable, and auditable.
Explainability
Every AI decision surfaces a human-readable rationale before execution.
Confidence scores and model version are stored with each output.
Audit Trail
All AI Gateway calls are logged with prompt, response, latency, and token count.
Logs are immutable and retained for 90 days (Enterprise: configurable).
Human Oversight
No automated action is taken on case data without an explicit approval step.
Operators can disable or sandbox any AI feature without a code change.
Your data is yours. We operate as a data processor under GDPR and apply privacy-by-design principles across the entire platform.
Storage & Encryption
Data encrypted at rest (AES-256) and in transit (TLS 1.3+).
Tenant data is logically isolated — no shared tables or cross-tenant joins.
Customer data is never used to train or fine-tune any AI model.
Regulatory Compliance
GDPR-ready: DPA available, right-to-erasure supported, data residency options.
CCPA-ready: no sale of personal information; opt-out controls built in.
Sub-processor list published and updated with 30-day notice of changes.
Fairness is not an afterthought. Our AI sourcing and decision features are evaluated continuously against bias benchmarks so outcomes remain equitable across protected groups.
Objective Scoring
Demographic proxies (name, nationality, gender, age) are explicitly excluded from match scoring.
Skill-based objective signals drive all ranking algorithms.
Continuous Evaluation
Quarterly bias audits run against fairness metrics (equalized odds, demographic parity).
Evaluation results are shared with enterprise customers on request.
Diverse Oversight
AI outputs are reviewed by a cross-functional ethics board before major model updates.
Red-team exercises are run on every new AI capability before general availability.
Security questions or vulnerability reports?
Contact our security team at security@state0.io. We operate a responsible disclosure programme with a 90-day remediation commitment.