Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

Trust Center

Modulos builds software that helps organizations govern their AI, so we hold our own platform to the standard we ask of our customers. This page collects our certifications, security documentation, policies and sub-processors in one place, and your security team can request the reports it needs for a vendor review.

Last updated 23 September 2026

Security contact: security@modulos.ai

Documents and reports

Public documents download straight away. Audit reports and detailed security material are shared on request: tick the ones you need and send a single request, and we email them to your work address. A few documents are reviewed by our team before they go out.

Compliance

  • Independent auditor's report on the design and operating effectiveness of our security controls.

    Requires approval
  • ISO/IEC 42001:2023 Certificate

    Certification of our AI management system.

Legal

  • Our standard DPA under GDPR and the Swiss FADP.

How we protect customer data

Our customers use Modulos to govern their own AI systems, which means our platform often holds sensitive information about their models, risks and controls. We treat that information with the same care we ask our customers to apply to their AI.

Independent audits
External auditors test our controls every year. The certifications at the top of this page come from those audits, and each card shows its validity date where one applies.
Automated control monitoring
We use Drata to monitor more than 100 internal security controls across the company. Evidence is collected automatically, which lets us demonstrate our security and compliance posture on any day of the year.
Encryption
Customer data is encrypted in transit with TLS and encrypted at rest.
Penetration testing
Independent security firms run network and application layer penetration tests every year.
Secure development
Manual and automated security and vulnerability checks run throughout our software development lifecycle.
People
Every employee completes security training each year and follows our policies for handling customer data.
Vulnerability disclosure
If you believe you have found a security issue in Modulos, email our security team. We investigate every report promptly.

Sub-processors

These are the third parties that process customer data on our behalf, with what they do and where the data is held. We update the list when a provider changes.

View all
  • Zitadel

    Identity Infrastructure Platform

    Data location: Switzerland

  • Langfuse

    LLM Tracing infrastructure

    Data location: Germany

  • Google

    Workspaces (storage, office, identity), GCP cloud compute services

    Data location: United States

  • HubSpot

    CRM

    Data location: United States

  • Microsoft Azure

    Cloud infrastructure and security

    Data location: Netherlands

  • CloudFlare

    CDN, DNS, DDoS protection

    Data location: United States

Have a security questionnaire?

Send it to our security team together with your timeline. Most answers already sit in the documents above, but we are happy to walk your reviewers through anything they need.