Security
Last updated: January 2026
Our approach
Security is inherited, not bolted on. Every enclave, gateway, and containment sensor is built on a pre-approved NIST SP 800-53 baseline, hardware-level isolation, and continuous attestation. See Solutions for how each layer is constructed.
Compliance & certifications
ServLogi maintains active authorizations across FedRAMP High, NIST SP 800-53, DoD SRG IL5/IL6, FIPS 140-3, HIPAA HITECH, SEC Rule 17a-4, SOC 2 Type II, ITAR, CJIS, IRAP, and CMMC Level 3. See the full list with descriptions on our Company page. Comprehensive third-party audit reports, SOC 2 Type II certifications, CMMC compliance documentation, and detailed System Security Plans are available exclusively to verified agencies and defense contractors under a mutual Non-Disclosure Agreement.
Responsible disclosure
If you believe you've identified a security vulnerability in ServLogi infrastructure, report it to our security team before disclosing it publicly. We investigate all credible reports and will acknowledge receipt within 2 business days.
- Email findings to [email protected] with reproduction steps.
- Do not access, modify, or exfiltrate customer data beyond what is required to demonstrate the issue.
- Allow reasonable time for remediation before any public disclosure.
Data protection
Memory is encrypted at the silicon layer (AES-XTS) inside every Sovereign Enclave, keys are ephemeral and customer-held, and cryptographic audit trails are sealed and immutable across Government Gateways.
Physical security
All hardware is housed in biometric cage vaults across our regions, with 24/7 monitoring and controlled physical access. See Infrastructure for region-level detail.
Incident response
Active telemetry, distributed honeypots, and ML-based attack profiling feed a continuous monitoring pipeline with SOC oversight and direct escalation to affected customers' security teams.
Contact our security team
For security-related inquiries, reach us at [email protected] or call our direct integration line at (925) 290-8130, available 24/7.
Take the next step
Reports reach our security team directly. For anything that is not a vulnerability, the other two routes are faster.
Report a vulnerability
Coordinated disclosure, with defined scope and expected response times. Send findings to our security team using the process set out above.
Check platform status and audits
The Trust Center carries live platform status, published control coverage, and audit summaries.
Review the control baseline
The fourteen accredited frameworks and the NIST SP 800-53 Rev. 5 controls the platform carries on your behalf.
CLOUD INFRASTRUCTURE