Trust center

Security, data handling, and compliance status at IQRush

Security, data handling, and compliance status at IQRush

Most AI visibility vendors publish a features page and call it trust. This page states what is actually true about IQRush’s security posture today, what is still in process, and what data we handle, so a security or procurement review has one accurate source instead of three.

01 / Overview

What IQRush does

IQRush measures how brands, products, and sources appear inside generative AI answer engines: ChatGPT, Copilot, Perplexity, Claude, Gemini, and the rest. We report those measurements as statistics with confidence intervals, not fixed numbers, because a single AI response is one draw from a probability distribution, not a fact about it.

Our customers are brands, agencies, and enterprise marketing teams. IQRush queries third-party answer engines, stores the responses for audit purposes, and runs classical machine learning, gradient-boosted models among them, to find the factors that drive AI answers. IQRush does not train language models. IQRush does not build foundation models.

02 / Summary

Security posture

The table states where each control stands today. Where a control is in process, we name the target rather than imply it is finished.

Area

Status

State

Cloud infrastructure

Single-cloud on Microsoft Azure, United States

LIVE

Customer identity

Dedicated identity infrastructure, OAuth 2.0

LIVE

Internal & admin access

Microsoft Entra ID

LIVE

Secrets management

Azure Key Vault

LIVE

Consumer personal data

Not collected or stored

LIVE

Third-party model training

No IQRush data used to train any provider’s models

LIVE

Security contact & acknowledgment

security@iqrush.ai, acknowledged within 2 business days

LIVE

Multi-factor authentication

Enforced for customer and administrative accounts

LIVE

Customer single sign-on (SAML)

Planned for enterprise customers

IN PROGRESS

Formal incident response program

Being documented; reporting path and notification commitment active today

IN PROGRESS

SOC 2 Type II

In process, initiating with Vanta

Q3 2026

Third-party penetration test

Planned engagement

Q3 2026

03 / Data

Data handling

IQRush does not collect or store consumer or data-subject personal data. The only personal data IQRush holds is the names and business email addresses of authorized users at customer and partner organizations, used for authentication and account management. Payment card data is handled by Stripe; IQRush does not store cardholder data. Full detail on data use, retention, and rights lives in our Privacy Policy.

What we hold

→ Business account information: name and business email, for login and account management.
→ Customer project configuration: brands, topics, competitors, and domains a customer chooses to measure.
→ Queries sent to answer engines and the responses returned, kept so measurements stay auditable and reproducible.
→ Standard application telemetry and usage logs.

What we do not collect

× Consumer or data-subject personal data.
× Behavioral tracking data about individual end users.
× Payment card data. Stripe holds this, IQRush does not.
× Special-category or sensitive personal data.

04 / AI Data Flow

AI provider data flow

Does IQRush let AI providers train on customer data?

No. IQRush queries each answer engine through its standard commercial API. None of these providers train their models on data submitted through those APIs.

Provider

Trains on API data?

Retention

OpenAI (Copilot, SearchGPT)

No, prohibited by default

Short-term, abuse monitoring only. Optional sharing disabled by IQRush.

Anthropic (Claude)

No, prohibited on commercial API data by default

Short-term. Optional sharing disabled by IQRush.

Google (Gemini, AI Overviews, AI Mode)

No, IQRush is on the paid non-training tier

Governed by Google’s paid-tier API terms

Perplexity (Sonar API)

No, non-training by default

Zero-retention by default

Mistral

Governed by Mistral’s API terms

Standard API terms

Precision note

No training and zero retention are not the same guarantee. No provider above trains on IQRush’s API-submitted data. Some retain data briefly on their side for abuse monitoring, measured in days, not months. IQRush has turned off every optional data-sharing setting on every provider account. As IQRush moves to enterprise API tiers, Zero Data Retention is being enabled wherever a provider offers it. Verification in progress: the settings above are being confirmed directly against each provider account and contract.

Verification in progress: the settings above are being confirmed directly against each provider account and contract. This note is removed once that confirmation is complete

05 / Infrastructure

Infrastructure

IQRush runs as a single-cloud environment on Microsoft Azure, hosted in the United States, primary region East US, with select machine-learning resources in East US 2. Running on one major cloud provider means IQRush inherits the physical, network, and platform controls Azure maintains under its own independent audits.

Application and API run on Microsoft Azure.

Structured data is held in Azure Database for PostgreSQL.

Stored answer-engine responses are held in Azure Blob Storage.

Public marketing and reporting pages are served from static hosting; these hold no customer measurement data.

Customer-relevant data stays inside IQRush’s Azure environment in the United States. IQRush does not currently offer EU or other regional data residency.

06 / Identity & Access

Identity & access

Customer accounts authenticate through dedicated identity infrastructure using OAuth 2.0. Internal engineering and administrative access to the Azure environment runs through Microsoft Entra ID, separate from customer login.

Is multi-factor authentication enabled?

Multi-factor authentication is enforced for both customer and administrative accounts.

Does IQRush support customer single sign-on?

SAML-based single sign-on for enterprise customers is on the roadmap and not yet generally available. Contact us if SSO is a requirement on your timeline.

07 / Incident Response

Incident response

How does IQRush respond to a security incident?

Security reports go to security@iqrush.ai. IQRush targets acknowledgment within two business days of receipt.

Internally, incident response is owned by a named member of IQRush leadership responsible for triage, containment, and coordinating any customer communication. If a security incident is confirmed to affect customer data, IQRush will notify affected customers without undue delay, and within 72 hours of confirming the incident, with what is known at the time and the steps being taken.

A fully documented incident response program, including severity classification and internal escalation procedure, is being finalized alongside IQRush’s SOC 2 readiness work. The reporting path and the notification commitment above are active today.

08 / Retention

Retention & deletion

How long does IQRush retain customer data, and can it be deleted?

IQRush retains project configuration, measurement runs, and stored answer-engine responses for the life of an active account, because historical runs are what make period-over-period and drift measurement possible. Account information for authorized users is retained for the life of the account.

On verified request or account termination, IQRush deletes customer data from production systems within 30 days. Provider-side retention at the AI layer is short and governed by each provider’s own terms; see AI provider data flow above.

A fully automated, documented retention schedule, including backup-cycle handling, is in progress as part of IQRush’s SOC 2 readiness work. Specific deletion terms can be set out in a data processing agreement on request.

09 / Subprocessors

Subprocessors

These third parties process data on IQRush’s behalf. Answer-engine providers are listed because IQRush sends queries to them and stores their responses; none train on that data, as detailed above.

Subprocessor

Purpose

Data accessed

Region

Microsoft Azure

Cloud infrastructure, database, storage, internal identity

All platform data

United States

OpenAI

Answer engine queried for measurement (Copilot, SearchGPT)

Queries and responses

United States

Anthropic

Answer engine queried for measurement (Claude)

Queries and responses

United States

Google

Answer engines queried for measurement (Gemini, AI Overviews, AI Mode)

Queries and responses

United States

Perplexity

Answer engine queried for measurement (Sonar)

Queries and responses

United States

Mistral

Answer engine queried for measurement

Queries and responses

EU / see Mistral terms

Firecrawl

Fetches publicly available web pages for measurement

Public web content only, no customer data

United States

Mailchimp

Transactional and account email

Business account name and email

United States

Stripe

Payment processing

Billing and payment data; IQRush does not hold cardholder data

United States

Static site host

Marketing and reporting site hosting

No customer measurement data

CONFIRMING

Confirming now: the specific host or hosts serving IQRush’s marketing and reporting sites are being verified before this row is finalized. Trafilatura, a self-hosted extraction library, also processes publicly available web content and runs inside IQRush’s own environment rather than as a separate hosted service.

This list reflects IQRush’s current subprocessors and is updated as our subprocessor set changes. Advance notice of subprocessor changes can be arranged through a data processing agreement.

10 / Compliance

Compliance status

IQRush is an early-stage company building a formal compliance program in a deliberate order. We state where we are precisely rather than imply a certification we do not hold. IQRush does not currently hold a SOC 2 report or other third-party security certification.

Initiative

Status

Target

SOC 2 Type II

In process, initiating our engagement with Vanta as our compliance-automation platform

Q3 2026

Third-party penetration test

Engagement planned, no external test conducted to date

Q3 2026

Customer SSO (SAML)

Product roadmap for enterprise customers

Roadmap

Formal security policies

Access control, incident response, and retention policies being documented alongside SOC 2 readiness

Q3 2026

Microsoft Azure maintains its own independent certifications, including SOC 2 and ISO 27001, at the infrastructure layer beneath IQRush’s application. Our privacy policy, terms of service, and data processing agreement are public. Our full Security Policy, Incident Response Policy, and any completed audit reports are available on request.

Request full documentation: email security@iqrush.ai with your company name and which document you need. We respond within two business days.

11 / Documents

Policies & reports

The documents below exist today or are in active preparation. Full text is available on request; summaries of each are already in the sections above. We do not publish a standalone vulnerability disclosure program yet. If you believe you have found a security issue, email security@iqrush.ai directly and we will respond within two business days.

Published

Privacy Policy and Terms of Service are published. Data Processing Agreement is available on request.

Available on request

Security Policy, Incident Response Policy, and Subprocessor Policy are available on request.

Upcoming reports

SOC 2 Type II Report and Penetration Test Report are not yet available; both are targeted for Q3 2026.

RESTRICTED

Enter the access password

This page holds the full text of IQRush’s Security Policy, Incident Response Policy, and Subprocessor Policy. If you were given a password as part of a security review, enter it below. Otherwise, email security@iqrush.ai to request access.

Content on this page is encrypted and only decrypts in your browser with the correct password.

Trust center

Security, data handling, and compliance status at IQRush

Most AI visibility vendors publish a features page and call it trust. This page states what is actually true about IQRush’s security posture today, what is still in process, and what data we handle, so a security or procurement review has one accurate source instead of three.

01 / Overview

What IQRush does

IQRush measures how brands, products, and sources appear inside generative AI answer engines: ChatGPT, Copilot, Perplexity, Claude, Gemini, and the rest. We report those measurements as statistics with confidence intervals, not fixed numbers, because a single AI response is one draw from a probability distribution, not a fact about it.

Our customers are brands, agencies, and enterprise marketing teams. IQRush queries third-party answer engines, stores the responses for audit purposes, and runs classical machine learning, gradient-boosted models among them, to find the factors that drive AI answers. IQRush does not train language models. IQRush does not build foundation models.

02 / Summary

Security posture

The table states where each control stands today. Where a control is in process, we name the target rather than imply it is finished.

Area

Status

State

Cloud infrastructure

Single-cloud on Microsoft Azure, United States

LIVE

Customer identity

Dedicated identity infrastructure, OAuth 2.0

LIVE

Internal & admin access

Microsoft Entra ID

LIVE

Secrets management

Azure Key Vault

LIVE

Consumer personal data

Not collected or stored

LIVE

Third-party model training

No IQRush data used to train any provider’s models

LIVE

Security contact & acknowledgment

security@iqrush.ai, acknowledged within 2 business days

LIVE

Multi-factor authentication

Enforced for customer and administrative accounts

LIVE

Customer single sign-on (SAML)

Planned for enterprise customers

IN PROGRESS

Formal incident response program

Being documented; reporting path and notification commitment active today

IN PROGRESS

SOC 2 Type II

In process, initiating with Vanta

Q3 2026

Third-party penetration test

Planned engagement

Q3 2026

03 / Data

Data handling

IQRush does not collect or store consumer or data-subject personal data. The only personal data IQRush holds is the names and business email addresses of authorized users at customer and partner organizations, used for authentication and account management. Payment card data is handled by Stripe; IQRush does not store cardholder data. Full detail on data use, retention, and rights lives in our Privacy Policy.

What we hold

→ Business account information: name and business email, for login and account management.
→ Customer project configuration: brands, topics, competitors, and domains a customer chooses to measure.
→ Queries sent to answer engines and the responses returned, kept so measurements stay auditable and reproducible.
→ Standard application telemetry and usage logs.

What we do not collect

× Consumer or data-subject personal data.
× Behavioral tracking data about individual end users.
× Payment card data. Stripe holds this, IQRush does not.
× Special-category or sensitive personal data.

04 / AI Data Flow

AI provider data flow

Does IQRush let AI providers train on customer data?

No. IQRush queries each answer engine through its standard commercial API. None of these providers train their models on data submitted through those APIs.

Provider

Trains on API data?

Retention

OpenAI (Copilot, SearchGPT)

No, prohibited by default

Short-term, abuse monitoring only. Optional sharing disabled by IQRush.

Anthropic (Claude)

No, prohibited on commercial API data by default

Short-term. Optional sharing disabled by IQRush.

Google (Gemini, AI Overviews, AI Mode)

No, IQRush is on the paid non-training tier

Governed by Google’s paid-tier API terms

Perplexity (Sonar API)

No, non-training by default

Zero-retention by default

Mistral

Governed by Mistral’s API terms

Standard API terms

Precision note

No training and zero retention are not the same guarantee. No provider above trains on IQRush’s API-submitted data. Some retain data briefly on their side for abuse monitoring, measured in days, not months. IQRush has turned off every optional data-sharing setting on every provider account. As IQRush moves to enterprise API tiers, Zero Data Retention is being enabled wherever a provider offers it. Verification in progress: the settings above are being confirmed directly against each provider account and contract.

Verification in progress: the settings above are being confirmed directly against each provider account and contract. This note is removed once that confirmation is complete

05 / Infrastructure

Infrastructure

IQRush runs as a single-cloud environment on Microsoft Azure, hosted in the United States, primary region East US, with select machine-learning resources in East US 2. Running on one major cloud provider means IQRush inherits the physical, network, and platform controls Azure maintains under its own independent audits.

Application and API run on Microsoft Azure.

Structured data is held in Azure Database for PostgreSQL.

Stored answer-engine responses are held in Azure Blob Storage.

Public marketing and reporting pages are served from static hosting; these hold no customer measurement data.

Customer-relevant data stays inside IQRush’s Azure environment in the United States. IQRush does not currently offer EU or other regional data residency.

06 / Identity & Access

Identity & access

Customer accounts authenticate through dedicated identity infrastructure using OAuth 2.0. Internal engineering and administrative access to the Azure environment runs through Microsoft Entra ID, separate from customer login.

Is multi-factor authentication enabled?

Multi-factor authentication is enforced for both customer and administrative accounts.

Does IQRush support customer single sign-on?

SAML-based single sign-on for enterprise customers is on the roadmap and not yet generally available. Contact us if SSO is a requirement on your timeline.

07 / Incident Response

Incident response

How does IQRush respond to a security incident?

Security reports go to security@iqrush.ai. IQRush targets acknowledgment within two business days of receipt.

Internally, incident response is owned by a named member of IQRush leadership responsible for triage, containment, and coordinating any customer communication. If a security incident is confirmed to affect customer data, IQRush will notify affected customers without undue delay, and within 72 hours of confirming the incident, with what is known at the time and the steps being taken.

A fully documented incident response program, including severity classification and internal escalation procedure, is being finalized alongside IQRush’s SOC 2 readiness work. The reporting path and the notification commitment above are active today.

08 / Retention

Retention & deletion

How long does IQRush retain customer data, and can it be deleted?

IQRush retains project configuration, measurement runs, and stored answer-engine responses for the life of an active account, because historical runs are what make period-over-period and drift measurement possible. Account information for authorized users is retained for the life of the account.

On verified request or account termination, IQRush deletes customer data from production systems within 30 days. Provider-side retention at the AI layer is short and governed by each provider’s own terms; see AI provider data flow above.

A fully automated, documented retention schedule, including backup-cycle handling, is in progress as part of IQRush’s SOC 2 readiness work. Specific deletion terms can be set out in a data processing agreement on request.

09 / Subprocessors

Subprocessors

These third parties process data on IQRush’s behalf. Answer-engine providers are listed because IQRush sends queries to them and stores their responses; none train on that data, as detailed above.

Subprocessor

Purpose

Data accessed

Region

Microsoft Azure

Cloud infrastructure, database, storage, internal identity

All platform data

United States

OpenAI

Answer engine queried for measurement (Copilot, SearchGPT)

Queries and responses

United States

Anthropic

Answer engine queried for measurement (Claude)

Queries and responses

United States

Google

Answer engines queried for measurement (Gemini, AI Overviews, AI Mode)

Queries and responses

United States

Perplexity

Answer engine queried for measurement (Sonar)

Queries and responses

United States

Mistral

Answer engine queried for measurement

Queries and responses

EU / see Mistral terms

Firecrawl

Fetches publicly available web pages for measurement

Public web content only, no customer data

United States

Mailchimp

Transactional and account email

Business account name and email

United States

Stripe

Payment processing

Billing and payment data; IQRush does not hold cardholder data

United States

Static site host

Marketing and reporting site hosting

No customer measurement data

CONFIRMING

Confirming now: the specific host or hosts serving IQRush’s marketing and reporting sites are being verified before this row is finalized. Trafilatura, a self-hosted extraction library, also processes publicly available web content and runs inside IQRush’s own environment rather than as a separate hosted service.

This list reflects IQRush’s current subprocessors and is updated as our subprocessor set changes. Advance notice of subprocessor changes can be arranged through a data processing agreement.

10 / Compliance

Compliance status

IQRush is an early-stage company building a formal compliance program in a deliberate order. We state where we are precisely rather than imply a certification we do not hold. IQRush does not currently hold a SOC 2 report or other third-party security certification.

Initiative

Status

Target

SOC 2 Type II

In process, initiating our engagement with Vanta as our compliance-automation platform

Q3 2026

Third-party penetration test

Engagement planned, no external test conducted to date

Q3 2026

Customer SSO (SAML)

Product roadmap for enterprise customers

Roadmap

Formal security policies

Access control, incident response, and retention policies being documented alongside SOC 2 readiness

Q3 2026

Microsoft Azure maintains its own independent certifications, including SOC 2 and ISO 27001, at the infrastructure layer beneath IQRush’s application. Our privacy policy, terms of service, and data processing agreement are public. Our full Security Policy, Incident Response Policy, and any completed audit reports are available on request.

Request full documentation: email security@iqrush.ai with your company name and which document you need. We respond within two business days.

11 / Documents

Policies & reports

The documents below exist today or are in active preparation. Full text is available on request; summaries of each are already in the sections above. We do not publish a standalone vulnerability disclosure program yet. If you believe you have found a security issue, email security@iqrush.ai directly and we will respond within two business days.

Published

Privacy Policy and Terms of Service are published. Data Processing Agreement is available on request.

Available on request

Security Policy, Incident Response Policy, and Subprocessor Policy are available on request.

Upcoming reports

SOC 2 Type II Report and Penetration Test Report are not yet available; both are targeted for Q3 2026.

RESTRICTED

Enter the access password

This page holds the full text of IQRush’s Security Policy, Incident Response Policy, and Subprocessor Policy. If you were given a password as part of a security review, enter it below. Otherwise, email security@iqrush.ai to request access.

Content on this page is encrypted and only decrypts in your browser with the correct password.

AI search visibility you can defend

Whether you're building, buying, or briefing on AI search, get decision-grade data that holds.

Book a demo

© 2026 IQRush. All Rights Reserved.

Site by ONBOX

AI search visibility you can defend

Whether you're building, buying, or briefing on AI search, get decision-grade data that holds.

Book a demo

© 2026 IQRush. All Rights Reserved.

Site by ONBOX

AI search visibility you can defend

Whether you're building, buying, or briefing on AI search, get decision-grade data that holds.

Book a demo

© 2026 IQRush. All Rights Reserved.

Site by ONBOX