Last Updated: August 1, 2025 | Version 1.0
Sovant AI is currently in beta. While we implement robust security measures, we are actively working toward formal certifications. This page transparently outlines our current security practices and roadmap.
Beta Status: Sovant is not yet SOC2 or ISO 27001 certified. We leverage certified infrastructure providers and follow security best practices.
All data is stored in Singapore (ap-southeast-1) for PDPA compliance and low latency for Southeast Asian customers.
Magic links, HttpOnly cookies, 15-minute OTP expiry
Key rotation, rate limiting, request validation
TLS 1.3 in transit, AES-256 at rest
Row-level security, tenant isolation
We comply with Malaysia's Personal Data Protection Act 2010:
While Sovant works toward its own certifications, our infrastructure providers maintain:
Provider | Certifications |
---|---|
Supabase/AWS | SOC2, ISO 27001, PCI DSS |
Vercel | SOC2 Type II |
Cloudflare | SOC2, ISO 27001 |
We welcome security researchers to responsibly disclose vulnerabilities.
For security inquiries, vulnerability reports, or compliance questions:
support@sovant.ai