Security

Security is a first-class product requirement

Enterprise AI teams trust Traivr with sensitive prompts, model outputs, and evaluation data. Here's how we protect it.

Role-based access control

Every permission is enforced server-side across trainer, client, and admin surfaces — never in the UI alone.

Encryption in transit and at rest

All traffic is encrypted, with sensitive fields held under application-level encryption.

Audit logging

Sensitive actions — approvals, payments, data exports — are logged with actor, target, and timestamp.

Project & tenant isolation

Each client organization's data, datasets, and workforce are isolated from every other organization.

Secure task workspaces

Task content is scoped to assigned, qualified workers, with no incidental exposure to other projects.

Data-retention controls

Configurable retention windows per project, with defined deletion workflows.

Reviewer identity separation

Reviewers see only what they're authorized to see — trainer identity is withheld by default.

Designed for SOC 2 readiness

Our control environment is built around SOC 2 Trust Services Criteria as we pursue formal certification. We do not yet hold SOC 2 certification.