Welcome to the Whirl AI, Inc. Trust Center. This portal is designed to provide a clear and accessible overview of our commitment to security, privacy, and operational excellence. Here, you will find detailed information about the practices and policies we have in place to protect your data and maintain your trust.
At Whirl AI, Inc., we are dedicated to ensuring the confidentiality, integrity, and availability of our technology and sensitive information. Our approach to trust is comprehensive, covering everything from how we manage our vendors to how we handle your data and maintain our systems.
Key aspects of our trust posture include:
- Robust Vendor Management: We carefully vet and monitor our third-party service providers to ensure they meet our stringent security and privacy requirements. This includes conducting risk assessments, maintaining a vendor register, and reviewing compliance reports annually. We also ensure that data processing agreements are in place with sub-processors, outlining necessary technical and organizational measures.
- Comprehensive Data Protection: Whirl AI, Inc. has a documented policy outlining procedures and technical measures to protect the confidentiality, integrity, and availability of data. We have a designated Data Protection Officer responsible for our organization-wide governance and privacy program, acting as a point of contact for authorities and data subjects. We also provide a contact mechanism for privacy-related requests or incident reports.
- Secure Operational Practices: Our internal policies, such as the Acceptable Use Policy, apply to all employees, contractors, and partners, ensuring the secure use of company IT assets, including intellectual property and AI compute environments. We track and evaluate security events to determine if they constitute an incident, and all incidents are managed according to company policies and procedures. We also maintain secure and supported configuration standards for system components and implement risk mitigation strategies for unsupported components. Furthermore, we utilize Software Composition Analysis (SCA) to check for policy and license compliance, security risks, and supported versions in our software components and libraries.
- Clear Communication Channels: We provide external communication mechanisms for customers and third parties to report complaints, failures, bugs, incidents, vulnerabilities, and requests for information, with defined service level agreements for responses.
This Trust Center serves as a central resource to demonstrate our ongoing commitment to maintaining a secure and trustworthy environment for all our users.
Self-Assessments
We are working on our security compliance. We can provide completed questionnaires upon request.
AI
We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.
ESG
We prioritize and take environmental, social, and governance (ESG) considerations seriously in our operations and decision-making processes.
Legal
We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.
Data Privacy
Privacy of customer data is top of mind. We follow industry best practices and follow all applicable privacy regulations.
Network Security
We protect our corporate network against external & internal threats.
Security Grades
We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.
Risk Management
We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.
Asset Management
We have strict asset management policies in place to ensure that all assets are accounted for and secure.
BC/DR
We have a business continuity plan in place to ensure that we can continue to operate in the event of a disaster.
Change Management
We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.

