Your data is in safe hands.
From encryption to access management, Drivetrain enforces rigorous standards to ensure your data stays secure, private, and compliant.

Audited controls supporting the integrity of your financial reporting.
.png)
Security, availability, and confidentiality controls protecting your data.

Certified to the global information security management standard.

Privacy-first controls for compliant processing of customer data.
Security, controls, and governance
built for finance teams
Enterprise-grade security
Drivetrain supports SAML 2.0 single sign-on (SSO) and SCIM provisioning, and works with any compliant identity provider, including Okta and Microsoft Entra ID. Google Login is available as a turnkey SSO option.
We also support multi-factor authentication (MFA) for added access security, and domain allowlisting, so only users from the domains you trust can be provisioned in Drivetrain.
Set access for each user or user group. You decide who can see, edit, and contribute to a report or model. Confidential compensation details can be masked, so planners see the totals they need to forecast while individual salaries stay hidden, even on drill-down.
The same controls follow your data into AI. Whether someone is accessing information through Drivetrain's AI or your preferred LLM, permissions carry over.
Get complete visibility into every action taken on the platform, by any user, through a detailed audit trail and change log.
And every number can be traced back to its source, so you can follow any figure down to the exact input and connected system it came from.
.png)
Trusted data handling
Customer data is stored in the region you choose: europe-west3 (Frankfurt, Germany) or us-east1 (Virginia, USA).
All data is encrypted at rest with AES-256 and in-transit with TLS v1.2.
Your confidential data remains secure and private. Drivetrain does not use your data to train or fine-tune any AI models.
.png)
AI oversight & explainability
Drivetrain's AI never changes anything on its own. It asks for your approval before modifying any model, report, or dataset.
A deterministic calculation engine produces every number, removing the risk of hallucination. And, each number can be traced back to its source, so you can verify it.
Can I hide salary and compensation detail from people who shouldn't see it — while still letting them see the totals?
Compensation can be masked at the individual level. Modelers still see the totals they need to forecast, like total compensation by team or department, but individual salaries stay hidden, even on drill-down.
Is my data used to train your AI models?
Drivetrain never uses your data to train or fine-tune any AI model, ours or a third party's.
What certifications do you hold, and can we get the audit reports? (SOC 1 Type II, SOC 2 Type II, ISO 27001)
Drivetrain maintains SOC 1 Type II, SOC 2 Type II, and ISO 27001 certifications, and is GDPR compliant. You can find the audit reports here. For more information, write to us at privacy@drivetrain.ai.
Does the AI respect my access controls, or could it surface data a user isn't allowed to see?
The AI operates within each user's permissions and can only work with data that the user is already allowed to see. If someone can’t view a metric in Drivetrain, they will not be able to access it through Drivetrain's AI either, or through any other AI connected via Drivetrain's MCP.
Are your AI models hosted in your own environment, or are they public models — and how is our data safeguarded when it's sent to a model?
Drive AI uses a mix of Drivetrain's own models and leading frontier models (e.g. from providers like Anthropic and OpenAI). Frontier models are accessed through enterprise agreements with zero-data-retention terms: your data is sent only to process your specific request, is encrypted in transit, is never stored by the provider, and is never used to train their models.
Serious about security?
Book a demo to see Drivetrain in action.

.png)