Trust

The trust page

What procurement and compliance teams need to evaluate Ankra: where our SOC 2 programme actually stands, what data we hold, and who processes it. No claims we cannot back.

Compliance

Where we are on SOC 2, honestly

No badges we have not earned. Here is the actual state of the programme and what already exists for your auditors.

Current status

Not yet audited - and we will not pretend otherwise

Ankra has not completed a SOC 2 audit. What is true today: we are building an information security management system against the SOC 2 Trust Services Criteria, and this page will state the moment that changes. If a vendor questionnaire needs more than what is published here, ask us directly.

What auditors can use today

The evidence trail is not waiting on a certificate - it is built into how the platform works:

  • Append-only audit log covering every administrative change
  • Role-based access control with built-in and custom roles
  • Attributed Git history - every change traces to an author, SHA, and timestamp
  • Exportable evidence, per organisation
Data handling

What we hold, and what we never see

The control plane works from metadata and encrypted credentials. The heavy, sensitive material stays inside your cluster.

What the control plane stores

  • Cluster, stack, and organisation metadata
  • Credentials, encrypted and held in Vault
  • Audit events for every administrative change

What never leaves your cluster

  • Container image contents and scan targets - scanning runs in-cluster
  • Unredacted logs - redaction happens at the source, before anything is sent
  • Plaintext SOPS secrets - decryption happens inside your cluster

Data residency

  • The platform is operated by Ankra UK LTD
  • Product analytics runs on PostHog's EU-hosted cloud
  • For current control-plane hosting regions, request our security documentation

How we handle personal data is covered in ourprivacy policy.

Sub-processors

Who processes data on our behalf

The third parties we rely on to run the platform. We keep this list short on purpose.

Sub-processorPurpose
Hetzner (EU)Control-plane hosting, EU data centres
Auth0 (EU tenant)Identity and authentication
StripePayments and billing
PostHog (EU)Product analytics, EU-hosted, consent-gated
SentryError monitoring
OpenRouterLLM routing for AI features on platform-managed keys
GroqLLM inference for AI features on platform-managed keys
Voyage AIEmbeddings for AI search and retrieval
Google WorkspaceTransactional and support email
MintlifyDocumentation hosting

When your organisation brings its own model API keys, AI requests go directly to the provider you chose and our AI sub-processors are not involved.

A data processing agreement is available on request -[email protected].

Go deeper

The detail behind this page

The technical controls, and the product documentation that backs every one of them.

Technical controls

The full controls matrix - identity, the AI surface, secrets, audit, cluster hardening, and vulnerability management - with the status of each control and the architecture behind them.

Product documentation

How each control works in practice - configuring MFA and roles, SOPS encryption, the audit log, cluster security, and the MCP server.

Get started

From prompt to production.
No tickets in between.

Describe what you want to ship and let Ankra's AI generate, deploy, and operate it. Free forever for small teams.

Free forever tierNo credit cardZero lock-in