Security
Last updated: June 2026
Security program
pepiko.ai uses role-based access, encryption in transit, audit trails, and operational monitoring to protect the systems and data behind our APIs. Access to production systems is limited to team members who need it to do their jobs, and administrative actions are logged for review.
Data protection
Data submitted to our APIs is encrypted in transit and used only to provide the service — never to train foundation models. Requests are processed for classification, routing, and debugging within agreed retention windows, and internal access to that data is restricted by role.
Monitoring and reliability
Our services are monitored continuously, and current status and incident history are public on our status page. We investigate anomalies and service incidents as part of our operational process, and communicate meaningful incidents through that page.
Vulnerability disclosure
If you believe you’ve found a security issue in pepiko.ai’s APIs, dashboard, or website, please tell us through our contact page. We treat security reports as a priority, ask that you give us a reasonable opportunity to investigate and address an issue before public disclosure, and won’t pursue legal action against good-faith, non-disruptive security research conducted under this policy.
Compliance
Our controls are designed for enterprise deployment and child-first AI products. As we grow, we’re working toward formal third-party certifications, such as SOC 2. Rather than claim a status we haven’t reached, we’ll publish those on our Trust Center as they’re actually completed.
Need more detail?
If your team needs a deeper security review — architecture details, sub-processor information, or a signed questionnaire — we’re happy to walk through our security program directly. Reach out through our contact page.
