Security

Security & Data Handling

Last updated: August 2026

Open, auditable by design

The Semantica core engine is MIT-licensed and fully open source. There is no closed binary, no obfuscated logic, and no hidden data path — every line that builds a context graph, traces a decision, or records provenance is readable on GitHub.

Open-source library

The Semantica Python library does not transmit any data to our servers. All graph computation runs locally within your own environment — your data, your infrastructure. No telemetry is collected from library users unless you explicitly configure an integration that does so.

This website

We collect minimal analytics and standard server logs — see the full breakdown in our Privacy Policy. We don't sell or share this data with third parties.

Hosting & Enterprise deployments

Semantica has no managed cloud offering, and no plans to build one — every deployment runs on infrastructure you control, whether that's our Hosting tier or a Custom Enterprise Deployment on-premise or in your own cloud. Encryption at rest and in transit, VPC isolation, full audit trails, and SOC 2 readiness are things we help you configure in your own environment, not certifications held by a service we operate.

Reporting a vulnerability

Found a security issue? Please report it privately rather than filing a public GitHub issue — email kaif@getsemantica.ai with details and, if possible, steps to reproduce. We aim to acknowledge reports promptly and will credit responsible disclosures unless you prefer to stay anonymous.