5

Enterprise-grade security

For the AI that powers your business, here is why you're safe with Whirl.

request a security review

certified + secured by:

Built by a team that has run Cyber at scale.

Second line goes here

We learned what enterprise-grade security takes, and put it into Whirl's DNA from day one.

Sunny Bedi, Co-Founder and CEO of Whirl AI
Mario Duarte

Trust in technology isn't built on perfection, but on the craft of the people and systems dedicated to stopping threats before they become a problem.

Mario Duarte

Security

Former CISO - Snowflake

READ THE OPEN LETTER

Jacob Salassi

LEAD ENGINEER

Formerly
Director Production Security Snowflake

Michele Freschi

Security ENGINEER

Formerly
Director Red + Blue Team Snowflake

Cameron Tekiyeh

DATA ENGINEER

Formerly
Senior Manager Data Security Analytics Snowflake

Your environment is yours alone.

Second line goes here

Whirl is not multi-tenant SaaS. Every customer is individually contained, eliminating the possibility of shared data.

VISIT THE TRUST CENTER

Dedicated infrastructure

Fully isolated AWS environments for each customer, single-tenancy protects your data from the ground up.

Immutable by design

Component updates require complete versioned and auditable, no interactive login to Production such as SSH.

Device-based access

Strongest authentication securely limits environment access to Whirl-managed devices, MFA with FIDO2 and more.

Whirl agentic systems have strict guardrails.

No data training

Your data is never used to train anything.

No proprietary models

Your data is not feeding a proprietary model, we do not run our own models.

No data sharing

Data isolation is consistent across the AI layer.

We are certified + compliant.

SOC 2 Type II

Audited annually against the AICPA Trust Services Criteria. Reports available on request.

Penetration testing

Tested by independent third parties. Findings tracked, remediated, and re-validated.

We partner with the security industry's best.

We trust Whirl AI with critical enterprise systems, and that trust holds at every layer of the stack. With Chainguard Containers, every image is rebuilt continuously from source, kept to minimal attack surface, and maintained with zero known CVEs.

Matt moore
Co-founder & CTO
Chainguard

When an AI platform asks for access  to the systems that run your business, identity can’t be an afterthought. Whirl AI built its architecture to secure that access without secrets from day one. Aembit is proud to provide that foundation.

David Goldschlag
CEO
AEMBIT

What your security and procurement teams want to know.

Is our data ever shared with other customers?

No. Every customer runs in a fully isolated AWS environment with no multi-tenancy. There is no shared infrastructure, so one customer's data has no path to reach another customer's data.

Do you train models on our data?

No. We never train models on your data or your configuration, and we do not run our own models. Whirl uses established model providers, and your data is not used to train anything.

What certifications do you hold? Can we see reports?

We have SOC 2 Type II certification, we are penetration tested, and our current controls  are published in our Trust Center we can share reports with your security team on request.

How do you protect credentials and secrets?

Access to our environment is limited to corporate devices with enclave-based authentication and FIDO2 MFA, and there is no SSH access.

We use Aembit for non-human identity to protect the secrets and keys that connect to your systems, so credentials cannot be lifted from a device or leaked.

Where does our data live?

Your data lives in a dedicated, fully isolated  AWS environment provisioned for your organization.

Who do we contact for a security review?

Reach out to our team to request a review. We will walk your team through Whirl’s security protocols.

Bring your security team, we'll walk you through everything.

REQUEST A SECURITY REVIEW

Ready to give us a Whirl?

CONTACT US