TRUST · v1.1·EARLY ACCESS · HONEST POSTURE

Trust at Read the Room.

We're early access. This page is the honest version of our security posture: what we have today, who we partner with for infrastructure, what we don't have yet, and what's on the roadmap. Everything below is true at the date this page was last updated.

LAST UPDATED · 2026-05-25 · OWNED BY FOUNDER

01 / WHERE YOUR DATA LIVES·Hosted on SOC 2 Type II infrastructure

Your scenario data never leaves audited infrastructure.

Read the Room runs on three vendors, each independently audited for security. We don't operate our own data centers. Your data lives entirely on infrastructure that has been formally certified.

Cloud Application Platform
VENDOR · 01
Application hosting, managed database, file storage, and global edge network
SOC 2 Type IIISO 27001GDPRHIPAA-ready
Real-Time Infrastructure
VENDOR · 02
Low-latency WebSocket servers powering live simulation events
SOC 2 Type II
Frontier AI Provider
VENDOR · 03
Large language models powering the AI Co-designer, Inject Advisor, and Bot Players
SOC 2 Type IIGDPRZero data retention
02 / HOW WE PROTECT IT·Engineering posture today

What's actually true about our security.

These are practices we've implemented and can demonstrate today. Not roadmap items, not aspirations.

  • [✓]Encrypted in transit (TLS 1.3) on every connection
  • [✓]Encrypted at rest (managed by our cloud platform and database providers)
  • [✓]Role-based access controls: every action attributed and audit-logged
  • [✓]Every decision, inject, deliverable, and export is timestamped and exportable
  • [✓]Daily automated backups (managed by infrastructure providers)
  • [✓]Two-factor authentication required on all admin and operator accounts
  • [✓]Principle of least privilege for internal access (founder-only today)
  • [✓]No customer data is used to train AI models; our AI provider operates with zero data retention
03 / WHAT WE DON'T HAVE YET·The honest roadmap

What we're working toward.

Some certifications take 6–18 months to obtain and cost $30k–$2M. We're pursuing them on a buyer-driven timeline. Listed here so you can make procurement decisions with eyes open.

[ ]
SOC 2 Type II of Read the Room as an organization
WHEN THE FIRST ENTERPRISE CONTRACT REQUIRES IT · EST. Q3 2026
[ ]
ISO 27001 certification
WHEN EU ENTERPRISE DEALS MATERIALIZE · EST. 2027
[ ]
FedRAMP (any baseline)
ONLY PURSUED WITH AN ACTIVE FEDERAL SPONSOR
[ ]
Signed DPA (Data Processing Agreement) template
AVAILABLE ON REQUEST · SIGN-READY TODAY
[ ]
Penetration test report
BUNDLED WITH SOC 2 TYPE II AUDIT
04 / QUESTIONS·Talk to the founder

Security questions get a same-day answer.

Procurement requirements, DPA review, specific compliance questions, or vendor-due-diligence packages. Request a demo and the founder will respond directly within 24 hours.

TRUST · CONTACT
Request a Demo
We'll connect you with the founder for any security or procurement question.
Book a Demo →

This page reflects our security posture as of 2026-05-25. We update it when the underlying reality changes. If you find something here that doesn't match what we tell you on a call, the call is wrong, not the page.