Ionworks
← All posts

Company news

July 9, 2025

Our Commitment to Security - Ionworks is now SOC2 compliant

Learn how we protect your simulation data and IP with end-to-end encryption, role-based access controls, and continuous monitoring.

Our Commitment to Security - Ionworks is now SOC2 compliant

At Ionworks, security is not an afterthought. It’s a responsibility we take seriously.

Battery teams rely on Ionworks to handle some of their most valuable data: simulation models, test protocols, performance results, and proprietary cell designs. As we’ve grown from Python-based tools into a complete cloud simulation platform, we’ve built security into every layer of our product and operations.

We’re proud to share that Ionworks is now SOC 2 Type I compliant, following an independent audit by Prescient Assurance.

For more details, visit security.ionworks.com.

What this means for you

SOC 2 is an industry-standard framework that evaluates how service providers manage customer data. This certification confirms that Ionworks has well-designed processes in place to protect:

  • Security: Preventing unauthorized access

  • Availability: Ensuring reliability and uptime

  • Confidentiality: Keeping your IP private and isolated

Compliance is more than a milestone. It reflects our long-term commitment to data protection, built into our platform and practices.

How we protect your data

We’ve implemented a multi-layered security program to protect your work from day one.

End-to-end encryption

  • TLS 1.2+ for data in transit

  • AES-256 for data at rest

  • Row-level security in Supabase for customer isolation

  • No public access to production environments

Role-based access and controls

  • Least-privilege permissions by default

  • Quarterly access reviews

  • Multi-factor authentication across internal systems

Ongoing monitoring and testing

  • Security scans run automatically on every code change

  • Oneleet provides real-time infrastructure and vulnerability monitoring

  • Annual penetration testing and continuous incident alerting via Slack

Backups and recovery

  • Data is backed up every 2 minutes

  • Recovery point and time targets are 1 hour and 4 hours respectively

  • Business continuity and disaster recovery processes are tested annually

Beyond compliance

With support from Oneleet, our security program stays current through automated checks and policy enforcement. These tools help us identify risks early and maintain high standards every day, not only during audits.

You can explore our policies and security posture at security.ionworks.com.

Looking ahead

SOC 2 Type I is a strong foundation. We’re now preparing for SOC 2 Type II, which evaluates how well our controls perform over time.

Security will continue to grow with the Ionworks platform, so you can focus on building better batteries with confidence.

Ready to learn more?

If you're considering Ionworks or already working with us, we’re happy to answer questions or walk you through the platform. Book a demo.

Your data is safe with us - and we intend to keep it that way.

Frequently asked questions

Type I evaluates whether the right security controls are designed and in place at a point in time. Type II then evaluates how well those controls operate over an extended period, typically six to twelve months. Ionworks is currently SOC 2 Type I compliant and is preparing for Type II.
Customer data is separated using row-level security in Supabase, with least-privilege access controls and no public access to production environments. Encryption is applied both in transit (TLS 1.2+) and at rest (AES-256).
Our policies, certifications, and live security posture are published at security.ionworks.com. Compliance documentation is available on request for teams running formal vendor reviews.
Data is backed up every two minutes, with a one-hour recovery point objective and a four-hour recovery time objective. Business continuity and disaster recovery procedures are tested annually.

Continue reading