SezuSezu

Security & Compliance

Most AI vendors hand you a SOC 2 and stop. Sezu certifies the data, the model, and the agency — with an auditable record of every decision the system makes on your behalf.

Sezu is a live AI operating environment, not a chat wrapper. Our customers entrust us with workforce knowledge, live field operations, and regulatory-sensitive tasks — so our security program governs all three: the data that enters the system, the models that act on it, and the agency the system exercises on your behalf.

Issued by 6Tech Services Inc.Veteran-ownedBel Air, MDData residency: United States

Certifications

Enterprise-grade assurance, with honest status.

In progress

SOC 2 Type II

Assessed with Vanta

On roadmap

ISO/IEC 27001

On roadmap

ISO/IEC 42001

Aligned

NIST AI RMF

The three layers we certify

Data, model, and agency — all governed.

01

The Data

  • Tenant isolation
  • U.S. residency
  • Encryption in transit and at rest
  • Contractual commitment that data is never used to train shared models
02

The Model

  • Governed model lifecycle under ISO 42001 practice
  • Impact assessment
  • Human oversight
  • Evaluation gates before any model or routing change ships
03

The Agency

  • Deny-by-default enforcement on every action the system can take
  • Immutable journal of every boundary it crossed, refused, or escalated

How we protect you

Mechanisms, not promises.

Aegis

Deny-by-default enforcement.

AI-DIG

Immutable decision journal (fail-closed logging).

Lumen

Private, isolated retrieval — per-tenant, with provenance, never used for training.

MCP

Least-privilege agents.

What you receive

The artifacts your security team needs.

  • SOC 2 Type II report under NDA
  • DPA + sub-processor list on request
  • Penetration-test attestation letter annually
  • AI system card
  • AI Assurance Addendum
  • AI-DIG log access
  • Pre-answered CAIQ / SIG-Lite questionnaires
  • Vulnerability Disclosure Program + incident SLA

Shared responsibility

What Sezu owns and what you own.

Sezu owns

  • Platform security, infrastructure, and availability
  • Model governance, evaluation gates, and change control
  • Immutable audit logging of system actions (AI-DIG)
  • Tenant isolation and data-residency controls

You own

  • Your data and the decision to capture it
  • User access management and role assignment
  • Classification of sensitive content and retention policies
  • Endpoint security and device policies for field hardware