Trust
Security practices, stated plainly.
3Stone AI is building a documented security program appropriate to an early-stage AI platform. This page describes current practices without implying certifications that have not been earned.
01
Current practices
Tenant-aware application controls, server-side secrets, canonical deployment guards, security headers, test coverage, documented incident response and vulnerability management form the present foundation.
02
Assurance status
3Stone AI does not currently claim SOC 2, ISO 27001, NIST certification, FERPA certification, HIPAA compliance, penetration-test attestation or a guaranteed uptime SLA.
03
Institutional review
A NIST CSF 2.0 current and target profile and an evidence-backed HECVAT draft are maintained internally for qualified review. Human approval and independent assurance remain separate steps.