generated: '2026-09-05' method: searched probe: true source: https://1up.ai/security url: https://1up.ai/security note: >- 1up has no trust portal in the Vanta/SafeBase/Drata sense — trust.1up.ai, 1up.ai/trust, 1up.ai/trust-center and 1up.ai/compliance all fail to resolve or return HTTP 404, and 1up.ai/llms.txt advertises a https://1up.ai/trust page that does not exist. What it does publish is a "Data Security & Privacy" page carrying three compliance badges as images, with no linked audit report, scope statement, audit period, auditor name or subprocessor list behind them. The help centre's procurement article confirms the report exists but is request-only: "Your IT team might ask us to complete a security review or to provide a SOC2 report." So: certifications are asserted publicly, artifacts are gated on sales contact. certifications: - SOC 2 Type 2 - ISO 27001 - GDPR evidence: - source: https://1up.ai/security kind: badge-image alt text items: - alt: AICPA SOC 2 Type 2 badge file: 69e84a84370417c58517b139_soc-badge.svg - alt: ISO 27001 badge file: 69e84b90c348d1f4c490a461_iso-badge.avif - alt: GDPR compliance badge file: 69c379b42014b7a7f533371d_badge-03.svg - source: https://help.1up.ai/en/articles/12995986-pricing-and-procurement kind: procurement guidance quote: >- Your IT team might ask us to complete a security review or to provide a SOC2 report. - source: https://help.1up.ai/en/articles/12997329-security-and-privacy-basics kind: security controls items: - AES-256 encryption at rest - AWS hosting with US / EU / AU data-residency choice - per-workspace data isolation - customer data never used to train models report_access: request-only via sales / security review dead_pointer_finding: >- https://1up.ai/llms.txt lists "Trust / Security: https://1up.ai/trust" among its authoritative sources. That URL returns HTTP 404. The live page is https://1up.ai/security.