Security & Trust

Last updated: June 2026 · Inkwell Technology Studios
This page explains how IAM.bot protects your data. It is an honest account of what is encrypted, what is not, who can access what, and how to report a vulnerability. We will update this page as the architecture evolves.

Encryption

Access controls

Subprocessors

ProcessorPurposeLocation
Neo4j AuraDBMemory graph storageUS / EU
AnthropicClaude model inferenceUS
Google Cloud PlatformInfrastructure, hostingUS / EU
Matrix.org protocolMessaging substrateSelf-hosted on GCP

Vulnerability disclosure

If you discover a security vulnerability in IAM.bot, please email security@iam.bot with a description of the issue. We will acknowledge within 48 hours and aim to resolve critical issues within 14 days. We do not pursue legal action against good-faith researchers.

What we are still building

We are actively working on: formal audit logging, a public status page, SOC 2 readiness, and a published security architecture diagram. We will add these to this page as they ship. We do not claim what we have not built.