--- title: "Security" description: "SOC 2 Type II, ISO 27001, ISO 27701, GDPR processes, security controls, and compliance documents." canonical: https://past.dev/security last-updated: 2026-10-10 --- # Security Source: https://past.dev/security past.dev is SOC 2 Type II audited, ISO 27001 and ISO 27701 certified, and GDPR compliant. The controls are audited every year. Reports are available on request. Trust center: https://security.revo.ai ## Certifications - SOC 2 Type II: An independent auditor tests whether the controls operated throughout the audit period. - ISO/IEC 27001: Independent certification of the information security management system. The scope includes access control, cryptography, secure development, supplier management, logging, and incident response. - ISO/IEC 27701: Privacy information management controls for processing, minimising, and retaining personal data, including data subject requests. - GDPR: GDPR processes cover data minimisation, retention, and data subject rights. A data processing agreement is available on request. ## How the API handles your data - Encryption in transit and at rest. Data uses TLS in transit and AES-256 encryption at rest. Stored integration credentials are also encrypted at rest. - Source retention. Ingested content is stored so recall results can cite it. Delete any ingestion with DELETE /api/v1/ingest/{id}, or ask us to erase a project. - Projects are isolated. A key is scoped to one project and cannot read another. On the MCP server the workspace is derived server-side, never a request parameter. - Model training. past.dev does not use customer data to train models. Model providers process requests with zero retention. - Restricted production access. Production access is restricted to the people who operate the service, logged, and inside the audit scope. ## Identity and access - API key revocation. The Memory API uses project-scoped keys, sent as a bearer header. Revoke a key at any time. - No standing credentials on MCP. Sign-in uses OAuth 2.1 with PKCE. Tokens are short-lived and bound by audience to the MCP endpoint. Each request derives permissions from the database. Requests with an unknown identity or permission are denied. - SSO integration. Workspaces with SAML or OIDC single sign-on authenticate through their own IdP, so MFA and conditional access carry over to past.dev unchanged. ## Operations - AWS, encrypted backups. The platform runs on AWS. Backups are encrypted. - Continuous monitoring. Operational monitoring and alerting run continuously. Vanta monitors compliance controls. - Independent penetration tests. An independent third party runs penetration tests annually. Findings are tracked to closure inside the audited process. - 15-minute notification. Affected customers are notified within 15 minutes of a confirmed security event. ## Frequently asked questions ### Is past.dev SOC 2 Type II compliant? Yes. An independent auditor tests whether the controls operated throughout the audit period. The report is available under NDA in the compliance pack. ### Is past.dev ISO 27001 certified? Yes. The information security management system is independently certified. ### Is past.dev ISO 27701 certified? Yes. ISO 27701 extends 27001 to privacy information management: how personal data is processed, minimised, retained and handled when someone exercises their rights. ### Is past.dev GDPR compliant? Yes. A data processing agreement and the current subprocessor list are available on request, and data subject requests are handled within the statutory windows. ### Does past.dev use my data to train AI models? No. past.dev does not use customer data to train models. Model providers process requests with zero retention. ### How is data deleted? Delete an ingestion immediately with DELETE /api/v1/ingest/{id}. Request project-level or account-level erasure from the past.dev team. ### Where does past.dev run? On AWS, with encrypted backups. The current subprocessor list is included in the compliance pack. ### Do you run penetration tests? Yes, an independent third party tests annually, and findings are tracked to closure inside the audited process. ### How do I get the SOC 2 report or a DPA? Open the trust center at https://security.revo.ai or write to support@past.dev. The current compliance pack includes the SOC 2 report, certificates, audit periods, and subprocessor list. The pack is updated after each audit cycle. ### How do I report a vulnerability? Write to support@past.dev. Security reports are prioritized. Compliance pack and DPA: https://security.revo.ai or support@past.dev.