Wentzel Trust Center
Security and trust, built into every product.
Wentzel builds AI-native software for high-trust and regulated workflows. This is where we show our work: how we protect your data, the frameworks we hold ourselves to, and how to reach our security team. Everything here is meant to be verified, not taken on faith.
Every Wentzel product runs on one shared security foundation — the Wentzel Compliance Baseline. Rather than bolt controls onto each app, we implement a single set of controls, map them once to SOC 2 and ISO/IEC 27001, and enforce them everywhere through mandatory code review, automated checks in our pipeline, and a hash-chained, append-only audit log. The result is consistent protection across the portfolio — and a trust center you can check, section by section.
Framework alignment
We design and operate to SOC 2 Type 2 and ISO/IEC 27001:2022. Until an independent auditor issues the report or certificate, we describe our status as Aligned — we do not say “compliant” or “certified” before the work is independently confirmed.
| Framework | Status | Independent assessment |
|---|---|---|
| SOC 2 Type 2 | Aligned | Engagement pending |
| ISO/IEC 27001:2022 | Aligned | Engagement pending |
For a prospect walkthrough, start at the framework posture diligence table — live-repo facts, zero third-party reports, no seed-fixture percentages.
How we protect your data
Encryption everywhere
Traffic is protected with TLS 1.3 in transit and encrypted at rest with managed keys. Sensitive fields are sealed with per-record envelope encryption before they ever reach a database.
Least-privilege access
Everyone signs in with phishing-resistant multi-factor authentication. Access is scoped to the minimum needed for the work and reviewed on a regular cadence.
A verifiable audit record
Privileged reads and changes are recorded as an append-only, hash-chained audit log, so each entry is cryptographically linked to the one before it. We are rolling out durable, tamper-evident storage with long-term retention to make that record independently verifiable end to end.
Built for resilience
Our products run on a global edge network with database point-in-time recovery and documented recovery objectives. Fleet availability is published at the Nexus status board (nexus.wentzel.ai/status). A dedicated status.wentzel.ai hostname is not live.
Responsible AI
We build with Anthropic’s Claude. Your data is never used to train AI models. Production model calls go through the authenticated Cloudflare AI Gateway. Direct-provider and AWS Bedrock transports are not enabled, and no HIPAA-tagged model path is live.
Deliberate vendor choices
We publish our subprocessor list, sign data-processing agreements, and intentionally exclude tools that don’t clear our security and privacy bar.
Explore the trust center
For auditors and enterprise customers: each section above carries the underlying control mapping and evidence pointers. A detailed auditor handoff packet is available to enterprise customers under NDA on request to security@wentzel.ai. The customer portal holds request instructions; packets are not self-serve downloads. No third-party penetration-test report or dated disaster-recovery drill report is on file yet; the packet marks both as pending.
Found a security issue? Reach our team at security@wentzel.ai or see our security.txt. We aim to acknowledge reports within 24 hours — that is a process target, not a measured SLA. Operated by Wentzel Investments LLC · last reviewed September 2026.