Information Security Requirements

Effective April 9, 2026

1. Information Security Program

ArchetypeID maintains a documented information security program aligned with industry standards. Controls are designed to prevent unauthorized access, modification, use, and deletion of Customer Property. The CISO reviews and approves security policies annually.

2. AI and Computational Engine Security

  • Zero-Retention Inference Routing: all prompts, data, and Customer Property routed through third-party foundational models are transmitted exclusively via enterprise-tier API endpoints configured for “Zero Data Retention.”

  • Model Data Segregation: Customer Property processed by ArchetypeID’s proprietary Macro-Behavioral Swarm Engine or Virtual Twins is logically isolated.

  • Prompt Injection Safeguards: ArchetypeID employs advanced input-validation and sanitization protocols designed to mitigate adversarial testing, prompt injection, and jailbreak attempts.

3. Technical Controls and Cloud Security

Centralized logging tools record activities, correlations, and changes in the production environment. Logs are scrutinized for anomalies and stored securely for a minimum of one year.


  • Encryption: Data in transit is encrypted using TLS 1.2 or higher with AES-256 signatures (defaulting to TLS 1.3). Data at rest is encrypted at the storage level using AES-256.

  • Key Management: ArchetypeID employs a cryptographic key management scheme that involves regular rotation of encryption keys. Keys are logically separated from Customer Property.

  • Access Control: Access to Customer Property is strictly authorized based on the Principle of Least Privilege. All access to production or administrative environments requires a unique user ID, complex passwords, and Multi-Factor Authentication (MFA).

  • Access Revocation: System access is revoked within twenty-four (24) hours of employee or contractor termination.

  • User Access Reviews: Semi-annual user access reviews are conducted to remove inactive and unnecessary accounts.

  • Environment Segregation: Logical and physical segregation is maintained between production and development/testing environments. Production data is never utilized in testing environments without explicit anonymization/de-identification.

  • Network Security: Serverless instances and a multi-tiered cloud network infrastructure. A Web Application Firewall (WAF) and Content Delivery Network (CDN) are deployed to mitigate DDoS attacks and guard against common web vulnerabilities (e.g., OWASP Top 10).

4. Vulnerability Management and SDLC

  • Vulnerability Scanning: weekly automated vulnerability scans. Identified vulnerabilities are patched and remediated according to our risk-based vulnerability management policy.

  • Penetration Testing: annual network and application-level penetration tests by independent, reputable third parties. Executive summary reports are available to Enterprise Customers upon written request under NDA.

  • Secure SDLC: secure code development practices integral to our agile release cycle, including mandatory peer code reviews, dynamic application security testing (DAST), and dependency/open-source vulnerability scanning prior to pushing code to production.

5. Operational and Personnel Controls

  • Personnel Security: all new hires undergo background screening (criminal and employment verification) prior to onboarding, as permitted by applicable law. Signing strict confidentiality and IP assignment agreements is mandatory.

  • Security Training: mandatory upon hire and annually thereafter. The curriculum includes incident reporting, device security, phishing awareness, and AI data handling best practices.

  • Device Management: centrally managed workstations with mandatory security controls, including full-disk encryption, password protection, remote-wipe capabilities, and inactivity lockouts.

6. Third-Party Risk and Incident Response

  • Third-Party Risk Management: robust vendor risk management program that ensures all Sub-processors maintain security standards equal to or greater than ArchetypeID’s.

  • Incident Response: documented and annually tested Incident Response Plan. In the event of a confirmed Data Security Breach, ArchetypeID will notify affected Customers in accordance with the timelines specified in the Data Processing Agreement.

  • Business Continuity and Disaster Recovery: disaster recovery plan for timely recovery in the event of major disruptions. Daily backups of Customer Property are conducted and stored securely across multiple availability zones.

7. Customer Audit and Testing Rights

Customer may not conduct penetration testing or vulnerability scanning against ArchetypeID’s production environments without prior, explicit written consent from ArchetypeID’s CISO. Any approved testing must adhere to strict Rules of Engagement designed to prevent service disruption (DDoS testing is strictly prohibited) and results must be shared confidentially with ArchetypeID.


  • Due Diligence: upon written request (no more than once annually), Customer may access documentation and standard security questionnaires demonstrating ArchetypeID’s compliance with these obligations.

8. Customer Security Responsibilities

  • Access Management: Customer is solely responsible for managing its authorized users, enforcing strong password complexity, and maintaining the security of its API keys and credentials.

  • Acceptable Use: Customer is responsible for ensuring that all data uploads and platform interactions adhere to ArchetypeID’s Acceptable Use Policy.