Trust Center
Modulos builds software that helps organizations govern their AI, so we hold our own platform to the standard we ask of our customers. This page collects our certifications, security documentation, policies and sub-processors in one place, and your security team can request the reports it needs for a vendor review.
Last updated 23 September 2026
Security contact: security@modulos.ai
Documents and reports
Public documents download straight away. Audit reports and detailed security material are shared on request: tick the ones you need and send a single request, and we email them to your work address. A few documents are reviewed by our team before they go out.
Compliance
Independent auditor's report on the design and operating effectiveness of our security controls.
Requires approvalISO/IEC 42001:2023 Certificate
Certification of our AI management system.
Legal
Our standard DPA under GDPR and the Swiss FADP.
How we protect customer data
Our customers use Modulos to govern their own AI systems, which means our platform often holds sensitive information about their models, risks and controls. We treat that information with the same care we ask our customers to apply to their AI.
- Independent audits
- External auditors test our controls every year. The certifications at the top of this page come from those audits, and each card shows its validity date where one applies.
- Automated control monitoring
- We use Drata to monitor more than 100 internal security controls across the company. Evidence is collected automatically, which lets us demonstrate our security and compliance posture on any day of the year.
- Encryption
- Customer data is encrypted in transit with TLS and encrypted at rest.
- Penetration testing
- Independent security firms run network and application layer penetration tests every year.
- Secure development
- Manual and automated security and vulnerability checks run throughout our software development lifecycle.
- People
- Every employee completes security training each year and follows our policies for handling customer data.
- Vulnerability disclosure
- If you believe you have found a security issue in Modulos, email our security team. We investigate every report promptly.
Sub-processors
These are the third parties that process customer data on our behalf, with what they do and where the data is held. We update the list when a provider changes.
Zitadel
Identity Infrastructure Platform
Data location: Switzerland
Langfuse
LLM Tracing infrastructure
Data location: Germany
Google
Workspaces (storage, office, identity), GCP cloud compute services
Data location: United States
HubSpot
CRM
Data location: United States
Microsoft Azure
Cloud infrastructure and security
Data location: Netherlands
CloudFlare
CDN, DNS, DDoS protection
Data location: United States
Have a security questionnaire?
Send it to our security team together with your timeline. Most answers already sit in the documents above, but we are happy to walk your reviewers through anything they need.