The trust page
What procurement and compliance teams need to evaluate Ankra: where our SOC 2 programme actually stands, what data we hold, and who processes it. No claims we cannot back.
Where we are on SOC 2, honestly
No badges we have not earned. Here is the actual state of the programme and what already exists for your auditors.
Not yet audited - and we will not pretend otherwise
Ankra has not completed a SOC 2 audit. What is true today: we are building an information security management system against the SOC 2 Trust Services Criteria, and this page will state the moment that changes. If a vendor questionnaire needs more than what is published here, ask us directly.
What auditors can use today
The evidence trail is not waiting on a certificate - it is built into how the platform works:
- Append-only audit log covering every administrative change
- Role-based access control with built-in and custom roles
- Attributed Git history - every change traces to an author, SHA, and timestamp
- Exportable evidence, per organisation
What we hold, and what we never see
The control plane works from metadata and encrypted credentials. The heavy, sensitive material stays inside your cluster.
What the control plane stores
- Cluster, stack, and organisation metadata
- Credentials, encrypted and held in Vault
- Audit events for every administrative change
What never leaves your cluster
- Container image contents and scan targets - scanning runs in-cluster
- Unredacted logs - redaction happens at the source, before anything is sent
- Plaintext SOPS secrets - decryption happens inside your cluster
Data residency
- The platform is operated by Ankra UK LTD
- Product analytics runs on PostHog's EU-hosted cloud
- For current control-plane hosting regions, request our security documentation
How we handle personal data is covered in ourprivacy policy.
Who processes data on our behalf
The third parties we rely on to run the platform. We keep this list short on purpose.
When your organisation brings its own model API keys, AI requests go directly to the provider you chose and our AI sub-processors are not involved.
A data processing agreement is available on request -[email protected].
The detail behind this page
The technical controls, and the product documentation that backs every one of them.
Technical controls
The full controls matrix - identity, the AI surface, secrets, audit, cluster hardening, and vulnerability management - with the status of each control and the architecture behind them.
Product documentation
How each control works in practice - configuring MFA and roles, SOPS encryption, the audit log, cluster security, and the MCP server.
From prompt to production.
No tickets in between.
Describe what you want to ship and let Ankra's AI generate, deploy, and operate it. Free forever for small teams.