Trust and Security
Last updated October 6, 2026
Centrum-AI processes sensitive supply chain data for manufacturers. We protect this data with documented policies, technical controls, and independent audits. This page tells you how we keep your data secure.
Organizational Security
Security Starts with Our Team
Information Security Program
Centrum-AI has a documented Information Security Program. We communicate this program to all team members. The program follows the SOC 2 framework. The American Institute of Certified Public Accountants (AICPA) created SOC 2. It is a widely used standard for security audits.
Third-Party Audits
Independent third-party auditors assess our security and compliance controls. These assessments follow the SOC 2 framework.
Third-Party Penetration Testing
An independent security company does a penetration test of our platform at least one time each year. We fix findings in order of severity. The testing company then does a retest to confirm the fixes. Customers can request a copy of our penetration test results.
Roles and Responsibilities
We define and document the roles and responsibilities for our security program and for the protection of customer data. All team members must read and accept our security policies.
Security Awareness Training
All team members must complete security awareness training. The training includes industry standard practices, phishing, and password management.
Confidentiality
All team members must sign a confidentiality agreement when they join Centrum-AI.
Reference Checks
We do detailed reference checks on all new team members before they join Centrum-AI.
Cloud Security
Hosted on Google Cloud
Cloud Infrastructure Security
All Centrum-AI services operate on Google Cloud Platform (GCP). Google has a comprehensive security program and many certifications, including ISO 27001 and SOC 2. For more information, refer to Google Cloud Security.
Data Hosting and Data Residency
We store all customer data in GCP. We host data for US customers in US data centers. We host data for EU customers in EU data centers, for example in Frankfurt, Germany. We follow the GDPR and country-specific data hosting requirements. We can use other GCP regions to meet these requirements.
Encryption at Rest
We encrypt all databases and stored data at rest.
Encryption in Transit
Our applications use only TLS encryption for data in transit.
Vulnerability Scanning
We scan our systems for vulnerabilities on a regular schedule. We monitor our systems for threats.
Logging and Monitoring
We log and monitor activity across our cloud services.
Business Continuity and Disaster Recovery
We configure backup, restore, and redundancy in GCP according to Google Cloud best practices. This decreases the risk of data loss if a hardware failure occurs. Monitoring tools alert our team when a failure affects users.
Incident Response
We have a written incident response plan for security events. The plan includes escalation procedures, fast mitigation, and communication.
Access Security
Access Only When Needed
Permissions and Authentication
Only authorized team members who need access for their role can access our cloud infrastructure and sensitive tools. Where available, we use Google Workspace single sign-on (SSO), two-factor authentication (2FA), and strong password policies.
Customer Sign-In Options
Customers can sign in to the Centrum-AI platform with a password and two-factor authentication. Customers can also sign in with OAuth.
Least Privilege Access Control
We give each team member only the access that their role needs.
Quarterly Access Reviews
Each quarter, we review the access of all team members to sensitive systems. We remove access that a team member no longer needs.
Password Requirements
All team members must follow our minimum password requirements for length and complexity.
Vendor and Risk Management
Risk Reviewed Every Year
Annual Risk Assessments
We do a risk assessment at least one time each year. The assessment identifies possible threats, including fraud.
Vendor Risk Management
Before we approve a new vendor, we assess the risk of that vendor. We then do the applicable vendor reviews.
Data Protection
Your Data Belongs to You
GDPR Compliance
We follow the requirements of the EU General Data Protection Regulation (GDPR).
Customer Data Separation
We keep the data of each customer logically separate from the data of other customers.
AI Model Training
We do not use customer data to train AI models for other customers.
Questions or Concerns
Send an email to security@centrum-ai.com if you:
Have a question or concern about security
Want to report a possible security issue
Want a copy of our penetration test results.