This FAQ describes how Secure.com protects customer data, governs its use of artificial intelligence, and identifies security responsibility between Secure.com and its customers. It is written for security teams, privacy and legal reviewers, and procurement functions evaluating Secure.com.
Secure.com is an AI-native Security Lifecycle Management platform. Its Digital Security Teammates carry out security work across detection and response, vulnerability management, and compliance operations. Because those Teammates act inside customer systems rather than only reporting on them, this document gives particular attention to how their access is scoped, how their actions are governed, and where human authority is preserved.
Answers here summarize Secure.com’s practices. Contractual commitments are set out in the customer agreement, the Data Processing Agreement, and applicable service documentation. Where those documents and this FAQ differ, those documents govern.
All five trust services categories — unqualified opinion, no exceptions
Certified, scope per Statement of Applicability
AWS Frankfurt (eu-central-1) or N. Virginia (us-east-1)
Customer data is never used to train foundation models
RTO 3 hours · RPO 12 hours
Incident notification aligned with GDPR timeframes