Skip to main content

MarutAI | The Science of Autonomy

MarutAI
Trust Center

Security and data practices

MarutAI works with proprietary data in environments where access, use, and model behavior must be controlled from the start.

This page explains how we handle customer data, what we use for model training, when information can reach a model provider, and the controls that protect each customer deployment.

Compliance & Assurance

AICPA SOC 2

Certified

SOC 2 Type II

Compliant

HIPAA

SOC 2 Type II provides independent assurance that the controls in scope operated over the examination period. It gives customers evidence to support security and vendor-risk review rather than asking them to rely on product claims alone.

MarutAI is HIPAA compliant and supports healthcare workloads that handle protected health information. Safeguards, data paths, access controls, and contractual requirements are established for each customer deployment.

Enterprise customers can request supporting security materials as part of diligence.

Customer Data

Customer data is used to build and operate the customer's own system. Our data practices are organized around four commitments.

Customer-owned

Customer data and the customer-specific artifacts built from it remain the customer's.

Purpose-limited

Customer data is used only to build, evaluate, operate, and support the system the customer has authorized.

Separated

Customer data is isolated by deployment and is not pooled into a cross-customer training corpus.

Customer-controlled

Customers choose the connected data sources, model providers, deployment environment, and approved data paths.

Model Training

MarutAI builds application-specific models. Training and improvement stay tied to the customer, the approved data, and the operating problem the system is designed to solve.

01

Customer-specific models

VATS builds and evaluates models using customer-approved operational data and synthetic regimes created for that application.

02

Customer-specific improvement

Catalyst uses evidence from a customer deployment to strengthen that customer's data foundation and subsequent model cycles.

03

No cross-customer training

MarutAI does not use one customer's content to train shared models or systems for another customer.

04

Third-party models

Customer data reaches a third-party model provider only when that provider is selected and configured for the deployment.

Data Paths and Providers

The deployment determines where data is processed and which external services can receive it. Provider access is configured, scoped, and visible to the customer.

Managed

MarutAI operates the service with customer data isolated to the customer deployment and the configured data paths.

Customer Environment

Customer VPC, private-cloud, on-premises, and hybrid deployments keep processing within the agreed customer boundary.

Air-Gapped

Air-gapped deployments can use local models without third-party model-provider egress.

Third-Party Providers

Information is routed to a third-party model or service provider only when that provider is selected and configured for the deployment.

Security Controls

These controls protect the systems and data used to deliver MarutAI services. They are part of the operating environment, not optional application features.

Identity & Access

Role-based access limits who can reach customer environments, data, and administrative functions.

Encryption

Customer data is encrypted in transit and at rest within MarutAI-managed services.

Secrets & Credentials

Credentials are deployment-scoped and kept separate from application code and model prompts.

Change Control

Versioned artifacts, approval gates, and deployment rings govern how changes move into customer environments.

Monitoring & Response

Security events, access activity, and material system changes are logged and handled through defined response procedures.

Provider Boundaries

Model and service providers are enabled deliberately for each deployment rather than receiving customer data by default.

Security Review

We support customer security, privacy, architecture, and vendor-risk reviews. Contact us to request diligence materials or discuss requirements for a specific deployment.