isotope13 LLC: Corporate Policies
Acceptable Use
Don't be a jerk. Don't break the law.
Access Control
You get the access you need and nothing more, reviewed regularly. Authentication requires a physical security key—no exceptions.
Artificial Intelligence
We use AI. We do not let models train on your data.
Business Continuity & Backups
Our production API endpoints run independently in 4 US regions. We back up all critical data.
Change Management
Every production change is documented, and every code and config change is reviewed before going live. Dev stays separate from production.
Compliance
We are working towards SOC 2 and GDPR compliance with annual third-party audits. Findings are tracked and fixed on schedule.
Data Lifecycle
We store no customer data. What we do hold is encrypted at rest and in transit.
Incident Response
Something breaks, we fix it fast. Critical incidents, security or otherwise, reach affected customers within 24 hours.
Physical Assets
Every device is tracked and fully encrypted. Retired devices are destroyed using NIST SP 800-88 techniques.
Risk Management
We assess risk yearly to spot threats and plan long-term mitigations.
Security Operations
We avoid running our own operating system stack. Where we must, environments stay patched, firewalled, and monitored, with critical patches applied within 8 hours.
Vendor
We avoid third-party vendors where possible. The ones we use face a yearly security review. See Approved Subprocessors.