Security

It runs quietly,
and holds up when you check.

Winglo runs continuously with access to your business data. That access is earned through architecture built for isolation, encryption, and governance, not bolted on after the fact.

Infrastructure principles
01 · Workspace isolation

Every workspace is fully isolated.

Winglo enforces workspace boundaries at every layer: database, application, and inference. Nothing crosses between workspaces, ever.

Runtime isolation log
08:42:17INFOtenant:acme-corpisolated
08:42:17INFOdb.partition:wsp_4a2bbound
08:42:18INFOinference.ctxscoped
08:42:18OKcross-workspace accessDENIED
08:42:19INFOagent.run:mkt_weeklylaunched
08:42:19INFOmemory.readworkspace-scoped
02 · Encryption

Always encrypted.

Not configurable because it is not optional.

at-restAES-256
in-transitTLS 1.3
03 · Regional residency

Only your region.

All customer data is hosted in the EU. No data leaves the EU without explicit instruction.

EU (Ireland)live
US (Virginia)roadmap
04 · Audit trail

Full provenance.

Every run is logged: input, output, model, timestamp, and the workflow that started it.

Workspace audit view
Retention by plan
Export on request
05 · Access control

Granular and revocable.

Role-based access. SSO on Enterprise. Revoke any AI department in one action.

RBACSSO (Enterprise)Instant revoke
AI governance

Your data doesn't train anything.

Winglo works with frontier model providers under no-training agreements. The data you connect is used to run the job you asked for. It is not used to train a model.

  • Your data never trains a model. That is a contract with every model provider Winglo uses, not a preference in a settings page.
  • You can export, archive, or erase the workspace and the data derived from it. Operational data is deleted within 30 days of a request. Audit logs follow within 90.
Compliance & reliability

What's live,
and what isn't.

Live controls first. Certifications when they exist. Nothing marked live that is still a plan.

Encryption & isolation

Live

AES-256 at rest, TLS 1.3 in transit, per-tenant isolation at the database, application, and inference layers.

Audit logs

Live

Every run is logged with input, output, model, timestamp, and workflow. Available in the workspace. Export on request.

GDPR alignment

Live

Customer data at rest is hosted in the EU. The DPA is public. Data-subject requests go through privacy@winglo.ai.

SOC 2 Type II

Roadmap

Planned. Formal audit process not yet initiated. Controls and evidence collection will begin ahead of GA.

HIPAA

Roadmap

Not currently supported. BAA capability and HIPAA-compliant infrastructure are on the product roadmap.

Penetration testing

Roadmap

Planned third-party pen test prior to general availability. Reports available under NDA on completion.

Security review

If you need to check, start here.

The DPA is public. Architecture notes and a named security contact go through the form. A countersigned copy is a conversation.