1. Architectural Scope & Role
When you use our website, we act as a Data Controller for basic contact inquiries. When enterprise customers deploy The Blue Iceberg Compliance & Trust OS or AI Gateway, we act as a Data Processor (or Business Associate under HIPAA) processing system metadata, evidence hashes, and telemetry strictly on the customer's authorization.
2. Information We Process
- System & Infrastructure Metadata: Cloud configurations, resource IDs, IAM role summaries, network mappings, and database metrics connected to the Company Map (e.g., AWS accounts, Neon Serverless PostgreSQL clusters, GitHub Enterprise repos, customer S3 storage buckets).
- AI Guardrail & Telemetry Data: Real-time token counts, model latency metrics, policy violation tags, and PII/PHI redaction counters processed through our low-latency inline gateway proxy.
- Cryptographic Audit Proof: SHA-256 state hashes, verification timestamps, and compliance milestone status indicators logged into the tamper-proof ledger.
- Account & Workspace Profile Data: Business contact information, administrative user IDs, SSO authentication tokens, and billing records.
3. AI Safety Rules, PII Masking & Zero Model Training
Strict Zero-Training Covenant: Neither The Blue Iceberg nor our underlying infrastructure vendors ever use customer prompts, model responses, system code, or audit evidence to train, retrain, or fine-tune public foundation models or shared machine learning weights.
Real-Time Sensitive Data Masking: When configured in the AI Control Plane, our gateway automatically inspects prompts and responses in real time, redacting Personally Identifiable Information (PII), Protected Health Information (PHI), credentials, and payment data before requests reach external or internal LLM endpoints. Prompts are evaluated in-memory with sub-millisecond execution and are not persisted in gateway cache.
4. Multi-Framework Compliance Standards
- AICPA SOC 2 Type II: Continuous monitoring of Trust Services Criteria for Security, Availability, and Confidentiality (CC6.1, CC6.6, CC7.1). Evidence is gathered via automated read-only API connectors rather than manual screenshot collection.
- ISO/IEC 27001:2022: Controls aligned with Annex A information security management, cryptography, access management, and vulnerability tracking.
- HIPAA Security & Privacy Rules: Full administrative, physical, and technical safeguards for electronic Protected Health Information (ePHI). We execute bilateral Business Associate Agreements (BAAs) with eligible enterprise customers.
- EU & UK GDPR: Processing of telemetry is executed on legitimate interests or contractual necessity (Article 6 GDPR). Customers maintain full control over Data Subject Rights, right to erasure, and automated telemetry opt-outs.
5. Tenant Isolation & Private Deployments
The Blue Iceberg Compliance & Trust OS enforces strict logical and cryptographic tenant isolation. Customer sandboxes, audit roadmaps, and evidence logs are partitioned by tenant IDs and protected by database row-level security and tenant-specific encryption keys.
For organizations with sovereign data residency requirements, we offer dedicated private cloud, hybrid, and air-gapped on-premise deployments where compute and telemetry remain entirely within the client's security perimeter with zero external data egress.
6. Tamper-Proof Audit Ledgers & Cryptographic Evidence
Evidence ingested from AWS, GitHub, or identity systems is hashed using industry-standard SHA-256 algorithms and committed to a sealed, immutable audit ledger. This guarantees that compliance records cannot be altered or retroactively manipulated, providing verifiable mathematical proof during formal third-party audits.
7. Data Retention & Deletion
We retain account details and compliance snapshots only for the active lifecycle of your enterprise subscription or as dictated by your compliance retention policies (e.g., 1-year or 7-year audit retention schedules). Upon workspace termination, all customer tenant containers, snapshot evidence, and temporary telemetry are cryptographically scrubbed and purged within thirty (30) days.
8. Subprocessors & Service Providers
We partner with enterprise-grade infrastructure providers (including Amazon Web Services, Neon Serverless PostgreSQL, and secure email dispatch providers) that maintain SOC 2 Type II and ISO 27001 certifications. A current list of approved subprocessors is maintained under customer bilateral agreements.
9. Contact & Privacy Officer
For privacy inquiries, BAA requests, or Data Protection Officer communications, contact privacy@theblueiceberg.com or theblueiceberg@gmail.com.