Anyray ← back to site

Security & Compliance

SOC 2 Type I Attested

Last updated: 17 July 2026

Anyray is self-hosted — your prompt and response content never leaves your environment, so most of a vendor security review is answered by the architecture itself. This section sets out how the software is secured and how data is handled.

Anyray holds an independent SOC 2 Type I attestation (as of 6 July 2026); other compliance references in this section are self-assessed.

Anyray completed its SOC 2 Type I attestation on 6 July 2026, independently examined by Securance Pro Assurance PLLC; a SOC 2 Type II examination is now in progress. An external penetration test was completed in July 2026 (no high or critical findings, remediation complete).

01The self-hosted model

The whole system — gateway, optimizer, console, and Postgres (the spend and trace store) — runs inside your cloud account. The only data that egresses is a content-free usage rollup for metering: counts, aggregates, and pseudonymous seat hashes, never prompt or response content.

This inverts the usual vendor trust boundary. You operate the software; your data stays with you. There is no vendor-side store of your content to breach, and no new vendor in your data path.

02How the software is secured

Operational detail. The control mechanics, environment variables, and endpoints behind each of these live in the product documentation at docs.anyray.ai/operate/security.

03Detailed practices

Each area below has its own page, written for a security reviewer working through a due-diligence questionnaire.

04Certifications & assurance

Anyray holds its own SOC 2 Type I attestation. And because the software runs in your environment, the attestation program for your deployment stays yours — Anyray supplies the control inventory and audit evidence to support it. Regulatory standing is detailed article by article on Risk Assessment.

Anyray holds a SOC 2 Type I attestation of its own program (as of 6 July 2026), independently examined by Securance Pro Assurance PLLC against the Security, Availability, and Confidentiality Trust Services Criteria; the report is available under NDA. A SOC 2 Type II examination is now in progress. An external penetration test of the vendor-operated surface was completed in July 2026 with no high or critical findings and remediation complete.

The one thing Anyray operates — the content-free metering/Portal backend — runs on AWS in the EU (Frankfurt): private-subnet compute behind a web application firewall, encryption in transit (TLS 1.2/1.3) and at rest (AES-256, AWS KMS), continuous threat detection and vulnerability scanning (GuardDuty, Inspector, Security Hub, AWS Config), and least-privilege access. It never receives prompt or response content.

05Contact

Email: security@anyray.ai