Bare Metal AI← Back

Security & Compliance

Last updated: June 19, 2026

BareMetalRT is built on a simple security premise: your data never leaves your hardware. Inference runs entirely on your own GPU, and chat content is encrypted on your device — it is never transmitted to, stored by, or readable by Bare Metal AI.

Architecture & Data Residency

Data Protection

Access & Identity

Infrastructure & Sub-processors

Hosted services run on vetted providers. We disclose every third party that processes data on our behalf on our Sub-processors page. None are engaged when the software runs offline or with Egress Mode sealed.

Compliance Status

Our strongest control is architectural: when inference runs locally or air-gapped, regulated data never leaves your hardware, which addresses the substance of most data-protection regimes by design. Certifications that require an independent audit (SOC 2, ISO) are listed honestly as planned — we do not claim certifications we do not hold.

FrameworkStatus
GDPR (data processing & SCCs)Available — via our Data Processing Addendum
CCPA / CPRA (California privacy)Available — we do not sell personal data; local inference keeps content on your device
HIPAA (PHI)Supported by architecture — in local or air-gapped operation PHI never reaches us; BAA available for hosted deployments
PCI DSS (cardholder data)Out of scope — we never store or process card data; payments handled by Stripe (PCI DSS Level 1)
NIST AI RMF & EU AI ActSupported — on-prem deployment and no-training-on-customer-data support your AI governance obligations
Air-gap / no-egress attestationAvailable — self-serve verification documented
SOC 2 Type IIPlanned — on our compliance roadmap
ISO 27001 & ISO 42001 (infosec & AI management)Planned — on our compliance roadmap

We do not claim certifications we do not hold. For the current status of our SOC 2 / ISO plans, a security questionnaire, a Business Associate Agreement, or to discuss specific compliance requirements, contact security@baremetalrt.ai.

Vulnerability Disclosure

If you believe you've found a security vulnerability, please report it responsibly to security@baremetalrt.ai. We will acknowledge your report and work with you on a coordinated disclosure. Please do not publicly disclose an issue before we've had a reasonable opportunity to address it.

Contact

Bare Metal AI, Inc. · security@baremetalrt.ai