Skip to content
Trust Center

AIzaadi Trust Center.

Self-serve answers about security, compliance, and data residency. No sales call required. Every claim here is factual, not marketing fluff.

Last reviewed: 2026-05-14

Checking status

Compliance status

PDPA-2023 (Pakistan)

Covered and documented

Lawful basis, purpose limitation, data minimization, and data subject rights enforced at the schema level. DPA available on request.

Read more

SOC 2 Type II

In progress (target 2027)

Readiness work scoped for 2027. Internal controls map available under NDA. We support customer-driven audits in the interim.

ISO 27001

Planned only if customer demand justifies it

Honest signal: not on the 24-month roadmap. Will revisit after SOC 2 if enterprise demand warrants the cost.

NAIP six-pillar alignment

Aligned across awareness, talent, ethics; gaps documented

Aligned with National AI Policy of Pakistan across awareness, talent, infrastructure, ethics, governance, and adoption pillars. Per-pillar evidence map available to public-sector customers.

SBP circulars (model governance, AML)

Covered via SBP-fraud-ops and governance tracks

Model governance, AML, and SBP IT and risk circulars are addressed in dedicated AIzaadi tracks. Customer-specific control matrices on request.

PVARA Act 2026

Not applicable (no VASP services)

AIzaadi does not custody, transfer, or exchange virtual assets. No VASP registration is required.

Sub-processors

NamePurposeRegionDPA status
Anthropic, PBCLLM inference for tutoring and content generationUnited StatesAvailable on request
OpenAI, L.L.C.LLM inference (fallback and specialized tasks)United StatesAvailable on request
Supabase Inc.Managed Postgres database and object storageTokyo, Japan (ap-northeast-1)Available on request
Hetzner Online GmbHCompute (API, worker, Redis)Falkenstein, GermanyAvailable on request
Resend, Inc.Transactional email deliveryUnited StatesAvailable on request

Data residency

Primary database: Supabase ap-northeast-1 (Tokyo, Japan). Tokyo chosen for low APAC latency from Pakistan and for separation from EU compute.. Compute: Hetzner Falkenstein, Germany (EU - GDPR adequacy).

Pakistan customers: data lives in Tokyo, served from Falkenstein DE compute. Cross-border under adequacy and contractual safeguards in our DPA. Tokyo was chosen for low APAC latency and separation from EU compute (a small latency tradeoff versus Mumbai, in exchange for jurisdictional separation).

Security measures

  • TLS 1.2+ in transit (TLS 1.3 preferred)
  • AES-256 at rest (Postgres + EBS + Storage)
  • Postgres RLS on every tenant-scoped table
  • No public DB exposure; short-lived JWTs only
  • Daily pg_dump backups (live as of 2026-05-14)
  • 2FA enforced for privileged users
  • CSP, HSTS, X-Frame-Options on every response
  • CSRF token on every mutating request

Recent posture changes

  1. 2026-05-14

    Daily digest opt-out (mig 0085)

    Learners and parents can now disable daily digest emails per-channel; consent is logged for PDPA evidence.

  2. 2026-05-12

    Lesson CMS audit log (mig 0086)

    Every lesson content edit by an admin is written to an immutable audit table with actor, diff, and timestamp.

  3. 2026-05-10

    Managed agents safety scaffolding

    Safety, Tutor, Reading, and Placement agents now run under a shared rate limiter and prompt-redaction layer.

  4. 2026-05-08

    Multi-branch tenancy and donor PDF

    Org-level branch isolation enforced through RLS; donor reporting PDF signed and timestamped.

  5. 2026-05-06

    Push notification consent flow

    Explicit consent recorded before any web-push token is registered; revocation honored immediately.

Downloads

Procurement pack is a POST endpoint. Logged-in users get org context injected automatically; otherwise a generic pack is returned.

Contact

Security reports: security@polymath.feerasta.ai

Data protection officer: privacy@polymath.dev

Note: security@ mailbox is being provisioned; inbound mail is routed to the DPO address until DNS lands.