Security at sference
How we protect your data while running large-scale GPU inference.
Infrastructure security
- Production runs in a dedicated AWS VPC (eu-central-1) with public/private subnet separation; all compute and data stores sit in private subnets.
- All traffic is encrypted in transit (TLS 1.3 at the load balancer; plaintext HTTP denied at the edge and at S3 bucket policy).
- All data at rest is encrypted (RDS, S3, EFS server-side encryption).
- Infrastructure is defined as code (OpenTofu) and reviewed via pull request with required checks.
- AWS API activity is logged via multi-region CloudTrail; Amazon GuardDuty provides managed threat detection with findings forwarded to on-call.
Your data
- Zero data retention (ZDR) tier: realtime request content is processed in memory and deleted when the request completes. Batch content is deleted on first download of results or after 30 days, whichever comes first.
- Inference content on our GPU workers is processed in memory only — never written to disk.
- Payment card data never touches our systems; payments are handled entirely by Stripe (PCI-DSS Level 1).
Access control
- All employee access to production requires SSO with multi-factor authentication; no shared or standing console accounts.
- Access reviews are performed quarterly; offboarding revokes access on termination day.
- Machine credentials are scoped to least privilege (worker tokens permit claim/result operations only).
Change management & monitoring
- All code changes require a pull request with passing CI checks and an approving review.
- Production is monitored 24/7 with CloudWatch alarms across service health, latency, error rates, and fleet capacity.
- Dependencies are scanned continuously (GitHub Dependabot, ECR image scanning); high-severity findings are remediated on a same-day target.
- Incidents are handled under a documented response process with root-cause analysis and corrective actions.
Compliance
sference is undergoing SOC 2 Type I attestation (Security, Availability, Confidentiality). Our GPU hosting providers hold independent certifications (Verda: SOC 2 Type II; Arctur: ISO/IEC 27001:2022).
Report a vulnerability
If you believe you've found a security issue, email [email protected]. We review every report and respond within 48 hours. Please do not publicly disclose until we've had a chance to address it.
Last updated: August 2026