Anyray ← back to site

Trust Center

Anyray is self-hosted: the gateway, optimizer, console, and datastore all run inside your environment, so your prompt and response content never reaches us. That architecture answers most of a vendor security review on its own. This page sets out the rest — our SOC 2 attestation, the controls behind it, and the documents you can pull directly.

Last updated: 28 July 2026

Compliance

SOC 2 Type I Attested As of 6 July 2026. Security, Confidentiality, and Availability, examined by Securance Pro Assurance PLLC.
SOC 2 Type II In progress Observation window underway; the Type II report follows the same Trust Services Criteria.
GDPR Aligned Self-hosting keeps you the controller. Article-by-article standing is on the Compliance page.
Penetration test Passed External test completed July 2026 — no high or critical findings; remediation complete.

The data boundary

Subprocessors in your deployment's data path: none. Because Anyray runs in your environment, no Anyray vendor processes your prompt or response content — there is no data-path subprocessor to enumerate. Your upstream model providers do receive prompts, but those are providers you select and contract with directly; Anyray only forwards to the endpoints you configure. The one Anyray-operated surface is the Portal account plane (sign-in, membership, billing, metering), which carries content-free metadata only. Full detail on Subprocessors and Data Protection.

Controls 56 IMPLEMENTED

Product Security | 5 controls

  • Secure SDLC integration
  • Change management
  • Vulnerability management
  • Configuration & patch management
  • Standard operating procedures

Access Management | 5 controls

  • Access rights
  • Credential management
  • Segregation of duties
  • Physical access control
  • Remote-work security

Data Security | 6 controls

  • Encrypted data at rest
  • Encryption key management
  • Secure data transfer
  • Data masking
  • Information classification
  • Data retention & destruction

Monitoring & Continuity | 7 controls

  • Security logging
  • Security monitoring & detection
  • Security incident management
  • Business continuity & ICT readiness
  • Disaster recovery planning
  • Network security
  • Resource capacity management

Organization Security | 13 controls

  • Risk management
  • Supplier & third-party security
  • Asset inventory
  • Security policy & awareness training
  • Security governance roles
  • Internal audit & management review
  • Legal, regulatory & IP compliance

Privacy & Data Protection | 12 controls

  • Data inventory and mapping
  • Lawful basis register
  • Data subject rights request workflow
  • Data protection impact assessments
  • Privacy by design and by default
  • Personal data breach response
  • Automated decision-making safeguards

Endpoint Security | 3 controls

  • Endpoint protection
  • Endpoint security baseline
  • Utility tool monitoring

Personnel Security | 5 controls

  • Human resources security
  • Personnel security screening
  • Disciplinary process
  • Physical & environmental security
  • Acceptable use

Reports & documents

Vulnerability Disclosure Policy PUBLIC Asset Inventory PUBLIC Risk Assessment PUBLIC
The penetration-test report, risk register, control-maturity ratings, and the full internal policy set (28 published policies) are shared under NDA on request — email security@anyray.ai and we will send them on the same NDA.

Documentation

Security & ComplianceTHE SELF-HOSTED MODEL, HOW THE SOFTWARE IS SECURED ComplianceCONTROLLER / PROCESSOR ROLES, SHARED RESPONSIBILITY Data ProtectionTHE DATA BOUNDARY, ENCRYPTION, WHAT IS STORED Risk AssessmentASSESSMENT PRACTICE, CADENCE, SOC 2 CONTROL MAPPING Asset InventoryEVERY DATA STORE, SECRET, AND SERVICE SubprocessorsWHO PROCESSES WHAT — AND WHY NOTHING IS IN THE DATA PATH Vulnerability DisclosureHOW TO REPORT A VULNERABILITY Privacy PolicyWHAT THE WEBSITE AND PORTAL COLLECT