Security and data practices
MarutAI works with proprietary data in environments where access, use, and model behavior must be controlled from the start.
This page explains how we handle customer data, what we use for model training, when information can reach a model provider, and the controls that protect each customer deployment.
Compliance & Assurance

Certified
SOC 2 Type II
Compliant
HIPAA
SOC 2 Type II provides independent assurance that the controls in scope operated over the examination period. It gives customers evidence to support security and vendor-risk review rather than asking them to rely on product claims alone.
MarutAI is HIPAA compliant and supports healthcare workloads that handle protected health information. Safeguards, data paths, access controls, and contractual requirements are established for each customer deployment.
Enterprise customers can request supporting security materials as part of diligence.
Customer Data
Customer data is used to build and operate the customer's own system. Our data practices are organized around four commitments.
Model Training
MarutAI builds application-specific models. Training and improvement stay tied to the customer, the approved data, and the operating problem the system is designed to solve.
Customer-specific models
VATS builds and evaluates models using customer-approved operational data and synthetic regimes created for that application.
Customer-specific improvement
Catalyst uses evidence from a customer deployment to strengthen that customer's data foundation and subsequent model cycles.
No cross-customer training
MarutAI does not use one customer's content to train shared models or systems for another customer.
Third-party models
Customer data reaches a third-party model provider only when that provider is selected and configured for the deployment.
Data Paths and Providers
The deployment determines where data is processed and which external services can receive it. Provider access is configured, scoped, and visible to the customer.
Managed
MarutAI operates the service with customer data isolated to the customer deployment and the configured data paths.
Customer Environment
Customer VPC, private-cloud, on-premises, and hybrid deployments keep processing within the agreed customer boundary.
Air-Gapped
Air-gapped deployments can use local models without third-party model-provider egress.
Third-Party Providers
Information is routed to a third-party model or service provider only when that provider is selected and configured for the deployment.
Security Controls
These controls protect the systems and data used to deliver MarutAI services. They are part of the operating environment, not optional application features.
Identity & Access
Role-based access limits who can reach customer environments, data, and administrative functions.
Encryption
Customer data is encrypted in transit and at rest within MarutAI-managed services.
Secrets & Credentials
Credentials are deployment-scoped and kept separate from application code and model prompts.
Change Control
Versioned artifacts, approval gates, and deployment rings govern how changes move into customer environments.
Monitoring & Response
Security events, access activity, and material system changes are logged and handled through defined response procedures.
Provider Boundaries
Model and service providers are enabled deliberately for each deployment rather than receiving customer data by default.
Security Review
We support customer security, privacy, architecture, and vendor-risk reviews. Contact us to request diligence materials or discuss requirements for a specific deployment.