Security you can verify.
SOC 2, GDPR, CCPA, and ISO 27001 posture below. Where we are attested, we say so. Where we are aligned but not certified, we say that too. Where the attestation is planned, we name the gap.
SOC 2, GDPR, CCPA, and ISO 27001 posture below. Where we are attested, we say so. Where we are aligned but not certified, we say that too. Where the attestation is planned, we name the gap.
Xerotier.ai operates inside colocation facilities that hold their own SOC 2 Type II attestations covering the security, availability, and confidentiality Trust Services Criteria for the physical environment. Xerotier.ai's own SOC 2 attestation is in progress; the report is not yet issued.
PlannedAligned with the General Data Protection Regulation. The platform implements data-subject controls including right-to-erasure, data export for portability, and anonymization. Contact contact@xerotier.ai to request a Data Processing Agreement.
AlignedConsumer rights for California residents are honored through the same data-subject controls used to satisfy GDPR (access, deletion, and portability). A dedicated CCPA "Do Not Sell or Share" workflow is planned; in the meantime requests sent to contact@xerotier.ai are honored within thirty days.
AlignedOur information security management system is designed to align with the ISO 27001 control families. Formal ISO 27001 certification is planned and not yet issued.
PlannedWe respond to DMCA notices and terminate repeat infringers. See /dmca for our designated agent and the notice and counter-notice process.
Use of the service is subject to US sanctions and export-control law. Denied-party and sanctioned-destination screening of accounts, payments, and model uploads can be activated per deployment; the control floor ships in every release.
Xerotier.ai allows you to choose where your data is stored by giving you full access to Xerotier Inference Microservice (XIM) nodes. Shared services are operated in the United States.
Enterprise customers can request XIM infrastructure with custom data residency requirements.
We provide a Data Processing Agreement (DPA) for customers who need to comply with GDPR and other data protection regulations. Contact contact@xerotier.ai to request a DPA; we respond within five business days.
If you discover a security vulnerability, report it to contact@xerotier.ai. We acknowledge responsible disclosure within one business day and aim to triage within five. A coordinated-disclosure window is negotiated per report.
Automated scanners and security researchers can fetch the machine-readable disclosure metadata at /.well-known/security.txt (RFC 9116).