SezuSecurity & Compliance
Most AI vendors hand you a SOC 2 and stop. Sezu certifies the data, the model, and the agency — with an auditable record of every decision the system makes on your behalf.
Sezu is a live AI operating environment, not a chat wrapper. Our customers entrust us with workforce knowledge, live field operations, and regulatory-sensitive tasks — so our security program governs all three: the data that enters the system, the models that act on it, and the agency the system exercises on your behalf.
Issued by 6Tech Services Inc.·Veteran-owned·Bel Air, MD·Data residency: United States
Certifications
Enterprise-grade assurance, with honest status.
In progress
SOC 2 Type II
Assessed with Vanta
On roadmap
ISO/IEC 27001
On roadmap
ISO/IEC 42001
Aligned
NIST AI RMF
The three layers we certify
Data, model, and agency — all governed.
01
The Data
- Tenant isolation
- U.S. residency
- Encryption in transit and at rest
- Contractual commitment that data is never used to train shared models
02
The Model
- Governed model lifecycle under ISO 42001 practice
- Impact assessment
- Human oversight
- Evaluation gates before any model or routing change ships
03
The Agency
- Deny-by-default enforcement on every action the system can take
- Immutable journal of every boundary it crossed, refused, or escalated
How we protect you
Mechanisms, not promises.
Aegis
Deny-by-default enforcement.
AI-DIG
Immutable decision journal (fail-closed logging).
Lumen
Private, isolated retrieval — per-tenant, with provenance, never used for training.
MCP
Least-privilege agents.
What you receive
The artifacts your security team needs.
- SOC 2 Type II report under NDA
- DPA + sub-processor list on request
- Penetration-test attestation letter annually
- AI system card
- AI Assurance Addendum
- AI-DIG log access
- Pre-answered CAIQ / SIG-Lite questionnaires
- Vulnerability Disclosure Program + incident SLA
Shared responsibility
What Sezu owns and what you own.
Sezu owns
- Platform security, infrastructure, and availability
- Model governance, evaluation gates, and change control
- Immutable audit logging of system actions (AI-DIG)
- Tenant isolation and data-residency controls
You own
- Your data and the decision to capture it
- User access management and role assignment
- Classification of sensitive content and retention policies
- Endpoint security and device policies for field hardware