AI security & data handling FAQ

How Embed protects customer data across every stage of AI-powered investigation

Security and compliance teams evaluating Embed can find detailed answers here about data handling, encryption, access controls, and how our AI processing works — without waiting on a formal security review.

group of white, blue and yellow 2D drawn rectangles

the embed agentic security platform

  • Investigates 100% of alerts
  • Reduces investigation time by up to 90%
  • Integrates with your existing security stack — no rip and replace

data protection & handling

Is my data secure?

Yes. Customer data is encrypted at rest and in transit, with security controls in place throughout the investigation process.

Is Embed SOC 2 Type II certified?

Yes. Embed has successfully completed a SOC 2 Type II audit, demonstrating that our security controls have been independently evaluated against the AICPA Trust Services Criteria.

Prospective customers can request the full SOC 2 report through the Embed Trust Center as part of the security review process.

Do you train on customer data?

Customer data is never used to train third-party AI models. Data is used only according to the terms of the customer agreement, and solely to deliver, improve, or secure the services the customer subscribes to.

How is sensitive data handled during AI processing?

Embed uses enterprise AI services hosted within AWS and Google Cloud. Customer data remains within those trusted cloud environments during processing and is never used to train foundation models. Both Amazon Bedrock and Google Cloud Vertex AI provide a contractual commitment that customer data is not shared for model training without customer authorization.

access & operational controls

What security controls are in place?

Role-based access, logging, least-privilege access, and full audit trails govern how Embed’s platform and personnel interact with customer data.

Do you consider historical events when triaging?

Yes, in two ways. Contextual enrichment pulls in relevant historical context for a new case based on what’s pertinent to that specific investigation. Targeted queries are issued to sources like the SIEM or EDR to gather additional information, selectively, based on what the investigation actually requires — not a blanket pull of all historical data.

AI trust & safety

Can the AI be manipulated or exploited by attackers?

Embed is designed to minimize the AI attack surface. While the platform primarily analyzes telemetry from security tools, we treat all externally sourced data as untrusted. We limit the ways that untrusted content can influence AI reasoning and employ multiple layers of protection to reduce the risk of AI-specific attacks.

How do you prevent hallucinated or fabricated findings?

We reduce that risk by keeping the AI tightly grounded in real evidence and structured logic:

  • Step-by-step investigations — the AI breaks investigations into small, focused steps instead of making big leaps.
  • Evidence-backed conclusions — every finding ties directly to supporting data.
  • Expert-built guardrails — our security team defines how investigations should work, and the AI operates within that framework.
  • Customer-specific context — we incorporate what’s normal in your environment so results stay accurate and relevant.
What happens if the system reaches an incorrect conclusion?

Every conclusion comes with the evidence and reasoning behind it, so incorrect outcomes are identifiable and reviewable. Misclassifications feed directly back into our improvement process, and the system is optimized to reduce false negatives.

How is explainability implemented?

We track where the evidence was derived as the investigation progresses, which lets us show and share the justification for each decision — the data reviewed, the steps completed, and the reasoning used.

Looking for product or investigation questions instead? Visit our AI SOC FAQ.