Featherless | Trust Center
Featherless Trust Center
Freedom to reliably deploy any open model effortlessly.
See section

Resources

Global DPA

FAQs

We're actively developing our SOC 2 program and have retained a reputable audit firm to begin our SOC 2 Type II observation period beginning September 1st, 2026. We expect to be SOC 2 Type II compliant and audited by Q1'27.
Reporting Security Vulnerabilities: The security of our systems and our users' data is a top priority at Featherless. We welcome reports from security researchers, customers, partners, and the broader community. How to Report: Please submit any suspected vulnerabilities to [email protected]. Please provide structured details about the issue, attach proof-of-concept files, and any relevant information. Our Commitment: We ask that researchers avoid privacy violations, disruption to production systems, or public disclosure of unverified issues while we investigate. In return, we commit to treating all researchers with respect, maintaining confidentiality, and working transparently with you through the remediation process.

Subprocessors

Cloudflare, Inc

Cloudflare, Inc

Monitoring

Continuously monitored by Secureframe
View all

Compliance

Monitoring

Change Management

Production Data Use is Restricted
Production data is not used in the development and testing environments, unless required for debugging customer issues.
Software Change Testing
Software changes are tested prior to being deployed into production.
Secure Development Policy
A Secure Development Policy defines the requirements for secure software and system development and maintenance.

Organizational Management

Information Security Program Review
Management is responsible for the design, implementation, and management of the organization’s security policies and procedures. The policies and procedures are reviewed by management at least annually.

Vulnerability Management

Third-Party Penetration Test
A 3rd party is engaged to conduct a network and application penetration test of the production environment at least annually. Critical and high-risk findings are tracked through resolution.

Risk Assessment

Vendor Due Diligence Review
Vendor SOC 2 reports (or equivalent) are collected and reviewed on at least an annual basis.

Network Security

Network Traffic Monitoring
Security tools are implemented to provide monitoring of network traffic to the production environment.
Automated Alerting for Security Events
Alerting software is used to notify impacted teams of potential security events.
Logging and Monitoring for Threats
Logging and monitoring software is used to collect data from infrastructure to detect potential security threats, unusual system activity, and monitor system performance, as applicable.

Communications

Privacy Policy
A Privacy Policy to both external users and internal personnel. This policy details the company's privacy commitments.