PDL Logo
PDL Legal& Compliance Center
← Back to Directory
ACTIVE POLICY

Trust Center

PsyData Labs (PDL) Trust Center

Welcome to the PsyData Labs L.L.C. (PDL) Trust Center. Earning and maintaining your trust is the foundation of our business. We are deeply committed to maintaining a state-of-the-art enterprise security, privacy, and artificial intelligence governance program. Our overarching strategy is built upon defense-in-depth principles across people, processes, and technology, strictly adhering to industry frameworks including SOC 2, ISO 27001/27701, NIST CSF, NIST AI RMF, GDPR, CPRA, NY SHIELD Act (NY GBL §899-aa), and the EU AI Act.

Real-Time Security Posture & Infrastructure Defense

At PDL, we recognize that point-in-time security assessments are insufficient. We employ continuous monitoring and maintain a dynamic, real-time security posture to proactively detect and defend against evolving threats.

  • Advanced Cryptography: All data in transit is secured using modern cryptographic protocols, strictly enforcing TLS 1.2+. Data at rest, specifically for S2+ data classifications and above, is protected using industry-standard AES-256 encryption. Key management lifecycles are strictly governed.
  • Identity and Access Management (IAM): We enforce a strict Least Privilege IAM model. All access requires explicit role-based approval, regular access reviews, and mandatory Multi-Factor Authentication (MFA) for all administrative, developer, and infrastructure access.
  • Vulnerability & Threat Management: Continuous automated vulnerability scanning and annual third-party penetration testing ensure the rapid identification of potential weaknesses, paired with strict internal remediation Service Level Agreements (SLAs).
  • Incident Response & Logging: Centralized SIEM logging, endpoint detection, and automated alerting empower our 24/7 incident response team. We enforce a 72-hour supervisory notification SLA where applicable under GDPR, CPRA, and the NY SHIELD Act.

Data Privacy, Classification & Subject Rights

Your privacy is embedded into our product architecture via Privacy-by-Design principles. We enforce a rigorous data classification taxonomy (S0–S4) to ensure the appropriate handling of all information, particularly within sensitive behavioral (D-BEH), psychological (D-PSY), and inferred (D-INF) data domains.

  • Data Subject Rights (DSAR): We guarantee the fulfillment of Data Subject Access, Deletion, and Correction Requests within statutory timelines, including 45 days for CPRA and one month for GDPR compliance.
  • Subprocessor Risk Management: Stringent third-party vendor risk assessments are completed prior to onboarding any subprocessor. Our Data Processing Agreements (DPAs) feature Article 28-style clauses, mandatory subprocessor notification, and strict data deletion protocols upon contract termination.
  • Data Residency & International Transfers: All cross-border data flows are safeguarded by Standard Contractual Clauses (SCCs) and comprehensive Transfer Impact Assessments (TIAs) where legally required.

Behavioral & Psychological Data Governance

As a pioneer in behavioral analytics and psychological signal processing, PDL applies unprecedented rigor to the collection, usage, and retention of highly sensitive human-centric data.

  • Lawful Basis & Consent Management: Data collection is strictly limited to disclosed purposes, heavily relying on explicit, verifiable user consent or other well-documented lawful bases.
  • Environment Segregation: Psychological signals and raw behavioral datasets are strictly barred from lower environments (e.g., staging, QA) unless fully anonymized and cryptographically scrubbed.
  • Inference Traceability: All inference outputs are securely logged with detailed explainability metadata for S3+ critical paths, ensuring full accountability in our predictive models.

Responsible & Ethical AI Governance

Our commitment to ethical AI development ensures that our machine learning models augment human capabilities safely, transparently, and without systemic bias.

  • Model Risk Tiering & HITL: All AI models undergo strict pre-deployment risk tiering. Any high-impact automated decisions mandate a human-in-the-loop (HITL) failsafe to prevent autonomous harm.
  • Bias Testing & Drift Monitoring: We perform continuous bias evaluation and model drift monitoring in production to detect and mitigate degradation in fairness, accuracy, and safety.
  • Strictly Prohibited Uses: Binding internal policies prohibit the use of PDL systems for unlawful discrimination, deceptive practices, or unapproved clinical and medical diagnostics.
  • Synthetic Data Controls: We utilize advanced synthetic data generation with robust differential privacy controls to prevent memorization leakage and protect underlying training subjects.

Compliance & Enterprise Attestations

Transparency and executive accountability are foundational to PDL's corporate governance structure.

  • Executive Oversight: Executive leaders and internal control owners complete binding annual compliance attestations to ensure top-down policy enforcement.
  • Continuous Audit Readiness: We maintain continuous external audit readiness for SOC 2 Type II and ISO 27001 alignments. Any security or privacy exceptions require written, time-bound approval paired with robust compensating controls.

Contact Our Compliance Teams

We believe in open, transparent communication regarding our trust, security, and privacy practices. For specific inquiries or to report concerns, please reach out to the appropriate channel:

  • Security Operations: security@psydata.org
  • Privacy Office: privacy@psydata.org
  • Legal Counsel: legal@psydata.org
  • Ethics & Compliance: compliance@psydata.org
Official Document Ledger Record

Trust Center

ID: PDL-TRT-001•REV: 1.1.0
Classification LevelPublic-Facing
Policy OwnerPDL Office of the Executives
StatusACTIVE
Effective Date2026-07-30
Review CycleAnnual
Authorized Signatory
Kyyle Everett Garrow
Kyyle Everett GarrowChief Executive OfficerExecutive Leadership