Trust & Compliance

Private by design, compliant by construction

We build private, high-control AI systems on infrastructure you own. Your data stays in your environment, and the system is engineered to work inside the laws and frameworks you already operate under. We support your compliance; final compliance is validated with your team and counsel.

How we keep your data safe

Every build inherits the same control baseline, whatever your industry.

You own the infrastructure

Every system runs on infrastructure you own: a dedicated cloud account, your own VPC, or fully on-premise and air-gapped. The code and the data are yours, not rented and not locked in.

Private, high-control deployment

When data control or compliance requires it, we deploy privately so sensitive data never leaves your environment. For air-gapped work we can run open-source or self-hosted models so inference stays local too.

Your data is never training data

We do not use your data to train third-party AI models without your explicit written consent. Cloud model providers we use are bound by the same restriction under our agreements.

Role-based access control

Least-privilege access, single sign-on, and role-based permissions so the right people see the right data, with ethical walls where a matter or case requires them.

Audit logging

Actions and access are logged so you have a defensible record of who did what and when, which is what regulators and auditors ask for.

Encryption in transit and at rest

Data is encrypted in transit (TLS) and at rest, with row-level security on the data layer where the stack supports it.

Human in the loop

AI informs and accelerates your team; it does not make the call on regulated decisions. People stay in the loop where the stakes require it.

Data residency and retention

You decide where data lives and how long it is kept. We build retention and deletion into the system so it matches your policy, not ours.

Frameworks we build to support

We engineer systems that support your obligations under the frameworks that apply to you. We do not sell certifications; final compliance is validated with your team and counsel.

HIPAA & HITECH

Healthcare practices, clinics, med spas

We build to meet your HIPAA and HITECH requirements, with access controls, audit logging, and encryption, on infrastructure you own so protected health information stays in your environment. We sign a Business Associate Agreement (BAA) on request. Final compliance is validated with your team.

GLBA Safeguards Rule & FTC Red Flags Rule

Auto dealerships, insurance, lenders

Dealerships and financial-adjacent businesses fall under the FTC Safeguards Rule and Red Flags Rule. We build the access controls, monitoring, and encryption those require, and keep customer financial data on infrastructure you own.

CJIS Security Policy

Law enforcement and public safety

For criminal-justice information we build to the CJIS Security Policy: advanced authentication, strict role-based access, audit logging, and on-premise or CJIS-aligned deployment so criminal justice information stays under your control.

FERPA & COPPA

Schools, districts, and edtech

Student records are protected under FERPA, and services touching under-13 users fall under COPPA. We build access controls and data handling appropriate for student data, on infrastructure you own, and never use student data to train third-party models.

TCPA & A2P 10DLC

Any AI phone or text outreach

AI voice and SMS agents are powerful and regulated. We build consent capture, opt-out (STOP) handling, and A2P 10DLC registration into outreach so your automated calling and texting stays inside the TCPA and carrier rules.

PCI DSS

Anyone taking card payments

We handle payments through PCI-compliant processors (such as Stripe) and design systems so card numbers are never stored on your servers, keeping your PCI scope small.

SOC 2 (audit-ready)

SaaS, tech, and B2B platforms

We build SOC 2-ready infrastructure, encryption, access controls, and audit logging, to support your own SOC 2 audit. Grid Theory does not sell a certification; we build the system so your auditors can sign off.

CCPA / CPRA & GDPR

Consumer and international data

For consumer and EU data we build the access, deletion, and consent controls these laws require, support data-subject requests, and can execute a Data Processing Agreement (DPA) so we act as your data processor.

Fair Housing Act & FCRA

Real estate and property management

Automated targeting and tenant screening are regulated. We build outreach and screening workflows that avoid discriminatory criteria (Fair Housing) and support adverse-action handling (FCRA), with a human deciding every regulated outcome.

FedRAMP / StateRAMP & Section 508

Government and municipalities

For public-sector work we build to FedRAMP or StateRAMP-aligned controls, Section 508 / ADA accessibility, and public-records retention, on infrastructure your agency owns and controls.

Agreements we sign

Business Associate Agreement (BAA)

Signed on request for HIPAA engagements, so we can handle protected health information on your behalf.

Data Processing Agreement (DPA)

Executed on request. We act as your data processor and handle personal data under your instructions.

Mutual NDA

We sign a mutual NDA before discovery so sensitive details stay confidential from the first conversation.

How we use AI providers

For cloud builds we use Anthropic (Claude) and OpenAI for AI features, under agreements that prohibit training on your data. For private or air-gapped deployments we can run open-source or self-hosted models so inference stays inside your environment. Our full subprocessor list and data-handling terms are in our privacy policy.

Read our privacy policy and terms for the full data-handling and subprocessor detail.

Have a compliance requirement? Let's scope it.

Tell us the frameworks you operate under and we will map out a private, high-control build that works inside them.

We use cookies to analyze site traffic and improve your experience. By accepting, you consent to the use of cookies for analytics and advertising purposes.