Where we stand, stated plainly
AI Rule Engine is built by a small team. We do not hold a SOC 2 attestation, we do not yet offer a DPA or a BAA, and the product has not had an independent third-party penetration test. Some vendors leave those facts to be discovered in the questionnaire. We would rather you know now.
What we do have is an architecture that makes the usual answer unnecessary for the deployments where it matters most. On a dedicated host the entire runtime lives inside your own Azure subscription, through an Azure Marketplace managed application. Every production run, its inputs and outputs, its trace, its logs, its uploaded files, and its AI prompts stay there. Paired with Azure OpenAI the model calls stay in your tenant too. The compliance boundary is one you already own and already assess.
Two things are ours whichever way you deploy, and we would rather name them here than have you find them later. The first is authoring: your rules, their version history, your user accounts, and the audit trail live in our control plane by design. The second is test data, which is the item on this page most likely to matter to you and least likely to be guessed.
If a current SOC 2 report or a signed BAA is a hard gate for you today, we are not a fit yet, and we will tell you that on the first call rather than the fifth.