We assess AI security.
We take ours seriously too.
Drel is built by security practitioners. We apply the same rigor to our own infrastructure that we help our customers apply to their AI systems.
What we actually do.
Your data is never used to train models
Assessment inputs are processed to generate your review and nothing else. Drel runs no model-training pipeline, and our AI provider on AWS neither trains on nor retains your inputs. There is no setting or opt-in that changes this.
Encrypted in transit and at rest
TLS 1.2+ in transit, AES-256 at rest. That includes assessment content, account data, and backups. There's no configuration where your data sits unencrypted.
We use Drel on ourselves
We review Drel's own architecture with Drel, including how it handles your data and the AI providers it relies on. We're not exempt from our own process — if anything, we're the most demanding customer.
Least privilege, no exceptions
Production access requires MFA and is scoped to what each person actually needs. When someone leaves or changes roles, access is revoked the same day.
Dependencies are not an afterthought
Dependencies are monitored for known vulnerabilities continuously, with automated update PRs and a weekly full audit that fails on high-severity issues. Fixes ship as they land, not on a quarterly schedule.
No security theater
We don't hold SOC 2 or ISO 27001 yet, and we say so. Until we do, your security team gets our controls, data map and sub-processors directly, in writing, in our trust pack.
Certifications & standards
Drel does not hold SOC 2 or ISO 27001 certification today. Instead of a badge, we give your security team the evidence directly: our controls, data map and sub-processor list.
Request our trust pack →Where your data lives
Your assessments never leave the EU. Every provider that handles your data works under contract and only on our instructions, and account data that leaves the EU is covered by the EU Standard Contractual Clauses.
Trust pack for security and procurement teams
Our data map, full sub-processor list, security controls and Enterprise commitments in one document, with our Data Processing Agreement alongside, so your vendor review starts with answers. Write to security@drel.ai — we reply within five business days.
Found a vulnerability?
We appreciate responsible disclosure. If you've found a security issue in Drel, please report it to us before going public. We commit to:
- Acknowledge your report promptly
- Keep you informed as we investigate and fix the issue
- Credit you in our security acknowledgments (if you wish)
- Not pursue legal action for good-faith research
Send your report to our security team. Please include a description of the vulnerability, steps to reproduce, and potential impact.
security@drel.aiPlease do not disclose publicly before we've had a chance to respond.