Security, the way we think about it.
Last updated April 2026
Data sovereignty, default
Every engagement is scoped to keep customer data inside the customer's environment. We deploy retrieval, reasoning, and automation components inside your cloud or on-prem footprint so sensitive content never touches our infrastructure.
Authentication & access
Account features on this site are backed by Supabase Auth with cookie-based sessions, row-level security, and email-and-password authentication. Production engagements run under whatever identity platform the customer already operates (SAML, OIDC, or equivalent).
Compliance alignment
Our default deployment templates align with SOC 2 Type II, HIPAA, and FedRAMP Moderate controls. Specific customer compliance requirements are addressed per engagement.
Responsible disclosure
If you believe you've found a security issue in something we run, email security@activemotion.ai. We aim to acknowledge within one business day.