generated: '2026-08-02' method: searched probe: true source: https://security.aidash.com/ url: https://security.aidash.com/ platform: Sprinto title: AiDash - Trust Center - Security & Privacy access: 'Public overview; policy documents and the SOC 2 Type 2 report are gated behind a "Request access" form.' certifications: - SOC 2 - SOC 3 - CSA STAR Level 1 certification_detail: - name: SOC 2 Type 2 status: certified detail: 'Reported by AiDASH as achieved with no exceptions for the fifth consecutive year.' evidence: https://www.aidash.com/security-compliance-and-responsible-ai/ - name: SOC 3 status: published detail: Public SOC 3 report, no access request required. evidence: https://www.aidash.com/wp-content/uploads/2026/05/AiDASH-Inc.-SOC-3-2026.pdf - name: CSA STAR Level 1 (CAIQ self-assessment) status: self-assessed detail: Listed on the Cloud Security Alliance STAR Registry since 2021-02-09. evidence: https://cloudsecurityalliance.org/star/registry/aidash/ policies_listed: - Information Security Policy - Operation Security Policy - HR Security Policy - Vulnerability Management Policy - Vendor Management Policy - Risk Assessment & Management Policy - 6 further policies (access-gated) security_practices: encryption: at rest and in transit for all customers key_management: AWS Key Management Service (KMS) backed by hardware security modules cloud_security_tooling: [AWS KMS, AWS GuardDuty, AWS Inspector] static_analysis: [CodeQL, TruffleHog, SonarQube] penetration_testing: third-party external penetration testing deployment: containerized; no customer-managed production servers evidence: - source: https://security.aidash.com/ http_status: 200 keywords: [soc 2, soc2, trust center, vulnerability management policy] - source: https://www.aidash.com/security-compliance-and-responsible-ai/ http_status: 200 keywords: [soc 2 type 2, soc 3, penetration testing, responsible ai] - source: https://cloudsecurityalliance.org/star/registry/aidash/ http_status: 200 keywords: [csa star level 1, caiq] notes: 'security.aidash.com returns HTTP 403 to some automated user agents; the body captured here was retrieved with an ordinary browser user agent (HTTP 200). No public vulnerability-disclosure contact, security.txt, or bug-bounty program was found — a "Vulnerability Management Policy" is listed but access-gated, so no VulnerabilityDisclosure or Security pointer is claimed.'