01 Security & trust

Enterprise-grade by architecture.

Bingo builds to the controls your security and risk teams expect — access, encryption, deployment, and governance — architected to SOC 2 and NIST 800-53, HIPAA-aligned, and governed by NIST AI RMF. Everything below describes how we design, build, and operate — and we'll walk your security team through the evidence behind each control.

SOC 2 Type II architected HIPAA-aligned NIST AI RMF ISO 42001-aligned Zero-trust SSO / RBAC US-based
02 Commitments in writing

Backed by contract, not just claims.

Enterprise buyers want assurances they can hold you to. Every control on this page is one we'll put behind a signature — and walk your security team through the evidence for.

  • Signed agreements before we touch data
    A BAA, DPA, or NDA in place first — with contractual breach-notification commitments.
  • Evidence walkthroughs, not just attestations
    We map our controls to your requirements and take your team through how each one operates.
  • Questionnaires turned around fast
    SIG, CAIQ, or your own — answered with specifics, by a named point of contact.
03 Access & identity

Zero-trust, least-privilege, by default.

Nothing is trusted because it sits inside the network. Every request is authenticated, authorized, and scoped to the minimum it needs — under your identity provider and your policies, not ours.

Identity & single sign-on

  • Zero-trust access model — verify every request, trust no network position
  • Enterprise SSO via SAML 2.0, OIDC, and OAuth 2.0
  • SCIM provisioning and deprovisioning against your directory
  • MFA enforced; no shared or standing credentials

Authorization & roles

  • Role-based access control (RBAC), with attribute-based (ABAC) policy where it fits
  • Least-privilege scopes — access mapped to the task, not the person
  • Just-in-time elevation with expiry, not permanent admin
  • Segregation of duties for anything consequential

Accountability

  • Every access decision attributable to a named identity
  • Session and access events written to an immutable log
  • Credential rotation and revocation on demand
  • Access reviews you can export for audit
04 Data protection

Encrypted, minimized, kept where it belongs.

Strong cryptography in transit and at rest, keys you can control, and a bias toward touching as little sensitive data as the job allows. Sensitive fields are redacted before they ever reach a model.

Encryption

  • AES-256 encryption at rest
  • TLS 1.3 in transit; mTLS for service-to-service
  • KMS-managed keys, with BYOK / customer-managed key (CMK) options
  • Centralized secrets management — no secrets in code or config

Minimization & redaction

  • PII / PHI redaction and tokenization ahead of processing
  • Data minimization — collect and retain only what the workflow needs
  • Configurable retention windows and defensible deletion
  • PHI excluded by default; enabled only under a signed BAA

Residency & boundaries

  • Data-residency controls to keep data in-region
  • Clear tenant and data boundaries — your data stays yours
  • Documented data flows and a data-processing inventory
  • No customer data used to train shared or third-party models
05 Deployment options

Runs inside your perimeter.

The system deploys where your policy says it must — your cloud account, your private network, your data center, or fully disconnected. We meet the boundary; we don't ask you to move data across it.

Private cloud

  • Deploy into your VPC / private networking
  • Private connectivity — no public exposure
  • Network segmentation between tiers and tenants

On-prem & self-hosted

  • On-premises / self-hosted deployment in your data center
  • Runs inside your existing infrastructure and controls
  • Your operators, your change management, your monitoring

Air-gapped

  • Air-gapped operation for fully disconnected environments
  • Offline model and update delivery
  • Hardened, segmented deployment topology
06 Assurance & testing

Security proven, not asserted.

Security is engineered into the delivery lifecycle and checked continuously — with the logs, scans, and runbooks a reviewer would expect to see. We are glad to walk your team through the evidence.

Testing & scanning

  • Penetration testing and ongoing vulnerability scanning
  • Static, dynamic, and dependency analysis (SAST / DAST / SCA)
  • Dependency and supply-chain review before release

Secure delivery

  • Secure DevSecOps pipeline — security gates in the build
  • Peer review and least-privilege build and deploy paths
  • Signed artifacts and reproducible releases

Monitoring & response

  • SIEM integration — stream events to your security stack
  • Immutable, append-only audit logging
  • Documented incident-response runbook, with contractual breach notification
07 Compliance alignment

Built to the frameworks your risk team expects.

We architect and operate to recognized control frameworks, and we meet your due-diligence process with evidence, documentation, and signed commitments.

Architected to SOC 2 Type II and NIST 800-53. HIPAA-aligned; BAA available. When your engagement requires specific attestations, we map our controls to your requirements, walk your team through the evidence, and put the commitments in contract.

Security controls

  • Architected to SOC 2 Type II and NIST 800-53 controls
  • NIST CSF 2.0-aligned control mapping
  • Immutable audit trails and evidence you can review

Healthcare & privacy

  • HIPAA / HITECH-aligned handling of PHI — and we'll sign a BAA
  • GDPR and CCPA / CPRA data-protection-by-design — and we'll sign a DPA
  • Data-subject rights and defensible retention built in

Diligence-ready

  • SIG and CAIQ questionnaire-ready
  • For public sector: architected toward FedRAMP / StateRAMP control baselines
  • Responsive to vendor security assessments and audits
08 AI governance

Verification is a primitive, not a feature.

Governing AI is our core competency, not an add-on. Consequential output is grounded in your sources, checked against evaluation thresholds, and routed through a named human owner before it acts — with the guardrails and monitoring a modern AI-risk framework expects.

Governance frameworks

  • Aligned with NIST AI RMF 1.0 and its Generative AI Profile
  • ISO/IEC 42001-aligned AI management practices
  • EU AI Act-ready — risk classification and documentation
  • Model-risk discipline informed by SR 11-7 thinking

Human oversight & grounding

  • Human-in-the-loop review for consequential output — nothing advances unverified
  • RAG grounding with citations back to your sources
  • Hallucination mitigation — answers grounded in source, not invented
  • Every override logged and fed back into the system

Evaluation & guardrails

  • Evaluation harness with accuracy thresholds and confidence scoring
  • Guardrails and prompt-injection defense on every input path
  • Drift monitoring and periodic re-evaluation in production
  • Model cards documenting scope, limits, and intended use

Vendor & data posture

  • Model- and vendor-agnostic — no lock-in to a single provider
  • No training on customer data, ever
  • Clear data boundaries between your workload and any external model
  • Provenance and versioning across models and prompts
09 Procurement & contracts

Easy to buy from. Easy to audit.

The paperwork your legal and security teams expect, founder-led US-based delivery, and your ownership of everything we build. We'll meet your process where it is.

The paperwork

  • We'll sign an MSA, SOW, BAA, DPA, and NDA
  • Scoped statements of work under a master agreement
  • Contractual breach-notification and security commitments

Ownership

  • Client owns the IP and the code we deliver
  • Documented handover and knowledge transfer every phase
  • No dependency by design — your team keeps what we build

Delivery & diligence

  • Founder-led, US-based delivery — no junior bench
  • Responsive to vendor security questionnaires and reviews
  • A named point of contact for security and compliance questions

Send us your security questionnaire — we'll turn it around.

SIG, CAIQ, or your own. Straight answers on architecture, deployment, and governance — with evidence behind every one.