Security & Trust
Security is part of the platform surface, not a separate product.
Clooney Network is built on the assumption that every request crosses a trust boundary. SOC 2 Type II controls, HIPAA-eligible data handling, four isolated regional planes, and a 99.97% trailing-twelve-month control-plane uptime are shipped infrastructure — verifiable by your security team before you book a demo.
Book a platform demoNo procurement required — 30 minutes, your stack or ours.
Trust register
What your security reviewer needs to pre-approve Clooney.
A scannable register of certifications, regional isolation, and uptime methodology. No marketing rephrasing — these are the published facts we hand procurement in the first email.
Audited annually. Report available under NDA through the demo intake form. Continuous monitoring on Drata for the in-scope control set covering logical access, change management, vendor risk, and incident response.
Business Associate Agreements executed on request for customers processing PHI. HIPAA-eligible since the Q4 2023 control refresh. Not yet FedRAMP authorized — we do not represent availability for federal workloads.
Four dedicated regional planes with separate control-plane tenants, KMS keys, and observability stores. EU customer data stays in EU-Frankfurt; AP customer data stays in AP-Singapore. In production since Q3 2023.
Measured at the Clooney orchestrator control plane, not at upstream foundation-model APIs we route to. Methodology, incident log, and exclusions published in our Master Service Agreement. Status page: status.clooneynetwork.com.
“We treat the control plane the same way we treat the routing engine — as code, with the same review bar. The 99.97% uptime figure is published, not aspirational, and the incident log below is the same one our CISO sends to enterprise customers. Trust is owned by an engineer with a pager, not delegated to a vendor relationship.”
By the numbers
The figures that travel alongside a security review.
The same numbers our account team attaches to procurement packets — drawn from the platform telemetry, not the marketing deck.
Incident log
Trailing-twelve-month platform incidents, published without NDA.
Every customer-impacting event on the control plane, with date, duration, region, scope, and the change we shipped afterward. Updated by the on-call engineering lead; the same log is sent to enterprise security reviews on request.
| Date | Duration | Region | Customer impact | Root cause | Resolution |
|---|---|---|---|---|---|
| 2025-11-04 | 17 min | EU-Frankfurt | Routed 2.1% of agent invocations to US-East fallback. No data loss; latency SLO briefly unmet for the affected subset. | Regional control-plane database failover exceeded its 15-minute recovery target due to a stalled WAL replay under bursty write load. | Replayed WAL buffers pre-warmed, failover target reduced to under 10 minutes. Postmortem published to customers the same day. |
| 2025-08-22 | 4 min | US-East | Trace ingestion queue rejected ~0.3% of spans for 4 minutes. Customer-facing routing unaffected; observability dashboards showed a gap. | Kafka consumer group rebalance under a scheduled deploy exposed a partition assignment bug introduced three weeks prior. | Sticky partition assignor pinned across deploys; pre-deploy rebalance linter added to CI. |
| 2025-05-17 | 42 min | AP-Singapore | Cost-routing decisions delayed for new sessions; existing sessions completed normally. Customer-visible only as elevated tail latency. | Dependency upgrade to a routing heuristic library regressed evaluation cache hit rate; cold-path latency exceeded the 99th-percentile target. | Library rolled back within 42 minutes; canary harness expanded to cover cost-routing heuristics at the unit level. |
| 2025-02-09 | 0 min | US-West | None — control-plane validation harness caught a misconfigured regional IAM policy before any production request path executed. | Drift between the Terraform module and the deployed IAM role on a secondary account; detected by the continuous-access-control check. | Policy reconciled; a second guardrail now blocks any CI run that would re-introduce the drift. |
Full postmortems for any of the above are available to qualified prospects under NDA — request via the demo intake form.
Next step
Book a 30-minute platform demo.
Walk your security and platform team through the control plane, the SOC 2 audit report under NDA, and the regional architecture for the workloads you are evaluating. Engineering-led, no procurement gate.