Trust center

Cellect AI security and compliance

Security controls, service providers, controlled policies, and assurance status for Cellect products. Fi is currently Cellect's only product.

Security answers

Current operating status

Does Cellect have a SOC 2 report?Current

Cellect is preparing for an initial SOC 2 Type I examination of its product environment and supporting production systems. Fi is currently Cellect's only product and is therefore the product in the present examination scope. No report has been issued, and Cellect does not represent itself as SOC 2 compliant or certified.

Who operates Cellect?Current

CellectAI Inc is currently owner-operated with no employees or contractors holding production access. Controls are designed for that actual operating model rather than assuming a larger security organization.

Where are Cellect products hosted?Current

Cellect's product environment runs on Cellect-managed infrastructure at a restricted-access facility in the United States. Fi is currently the only product in that environment. Detailed network and physical-location information is shared only when appropriate during a security review.

How is physical access restricted?Verifying

The physical-control design restricts building and equipment-area access to authorized people, with Cellect's owner currently the only person authorized for production equipment. The current evidence review is validating entry controls, inspection records, visitor handling, and environmental safeguards before this control is presented as verified.

How is customer access separated?Current

Cellect's current product, Fi, applies organization, company, project, and capability-level authorization. A user without an explicit resource grant cannot view that resource, and administrative routes require elevated authorization. New products must define and test equivalent access boundaries before handling customer data.

How are users authenticated?Current

Cellect product access currently uses centralized identity and short-lived application sessions. Fi is the current implementation. Administrative access is distinct from ordinary customer access.

View all security answers

Type I preparation

Readiness work in progress

These items are part of the current readiness plan and remain incomplete.

Policy approval13 version 1.1 policy drafts are prepared; formal approval and effective dates remain outstanding.
Independent testingA SOC 2 report and independent penetration test are planned as later readiness steps.
Administrative accessNamed, constrained, and retained privileged-access logging improvements are planned.
Backup resilienceBackups are encrypted; a separately located encrypted copy is planned.
AI data settingsProvider retention and zero-data-retention settings are being verified provider by provider.

Document access

Restricted documents

Approved policies and available internal documents are shared after manual review. Planned reports are clearly labeled and cannot be downloaded.

Request access