Security

Your design stays on machines you control.

The work this loop does is only useful on designs a company will not upload. So the deployment rule is simple: the model, the traces, and the tools run where the design already lives. We do not have a SOC 2 report, and this page does not pretend we do.

What SOC 2 is

SOC 2 is an audit, not a product feature and not a government license. The name is System and Organization Controls 2. A company hires an independent accountant to check whether its security practices are written down and actually followed. The checks cover some of five topics: security, availability, confidentiality, processing integrity, and privacy. Most customers ask about the first three.

A Type I report says the controls were designed sensibly on one date. A Type II report says they operated over several months, often three to twelve. The report buyers ask for is Type II. Having one does not mean the software has no bugs. Lacking one does not mean the data is exposed. It means nobody independent has reviewed the operating record.

We have not commissioned that audit. A line that says “SOC 2 aligned” would mean we like the criteria. It would not mean an auditor has looked. We will not use it until a report exists, and we will say Type I or Type II when it does.

What a pilot actually runs

Before any of your files move, the contract names the machines, who can log in, what is logged, how long traces are kept, and whether weights trained on your data are allowed to leave. The default we will write down:

An air-gapped install is the strict form: no route from those machines to the public internet. A private cloud network with your own keys is the form most hybrid teams can stand up faster. A short discovery session can also run on a design you are already willing to share, with logs deleted when the session ends. We will not describe that third path as a place to put a tape-out database.

What our own experiments used

The published results did not use customer designs. The tasks are ones we wrote: a small exponential unit, and processor specs in ChipBench. Training and evaluation ran on rented GPUs. Those runs are evidence about the loop. They are not evidence about a customer’s network.

If you want the security conversation before the technical one, write to contact@evolvinglab.ai. Ask where the machines sit, who can see a trace, and what happens to weights trained on your block. Those are the questions this page is for.