Trust Center
Last updated: 12 September 2026
What the platform is
Decisions Lab is a behavioural simulation platform. Customers describe an audience, we build personas for the individuals in it, and simulations run against those personas. All infrastructure and all subprocessors are in the United States.
Documents
Encryption and AI
Encryption and secrets
TLS 1.2 or higher for all client to server and service to service traffic. AES-256 at rest across all of our databases and object storage. Production credentials are held in a dedicated secrets manager, never in source code or version control.
AI providers
We use OpenAI and AWS Bedrock for AI inference. Material you submit for a simulation is sent to them at request time. Our OpenAI account is configured for zero data retention, so it is not stored. AWS Bedrock does not store it or use it for training. No customer data is used to train any model, ours or a third party's.
Subprocessors
| Vendor | Purpose | Region |
|---|---|---|
| Application hosting services | United States | |
| Database services | United States | |
| Authentication and user management services | United States | |
| Cloud hosting services | United States | |
| Database services | United States | |
| Storage services | United States (Virginia) | |
| Generative AI and AI model inference services | United States | |
| Generative AI and AI model inference services | United States (Virginia) | |
| Log aggregation and monitoring services | United States | |
| Analytics services | United States |
Formal assessments
Decisions Lab does not currently have a completed SOC 2 report and is not yet formally in audit. Our roadmap targets SOC 2 Type I with an initial scope focused on Security criteria.
Until then we can share, on request: a security overview, subprocessor summary, data residency summary, controller and processor position, policy summaries, and an incident reporting contact. Email security@decisionslab.io.
Security contact
security@decisionslab.io