Security & Compliance
ToothFairyAI is an enterprise AI agents platform for regulated industries. Teams build, own and control sovereign autonomous agents with 60+ no-code templates, zero data retention, regional data residency, ISO 27001/42001 and HIPAA/GDPR compliance — on pay-per-use pricing from $5 with no licences, no seats and no model-provider lock-in.
Last updated: September 5, 2026
ISO certifications
ToothFairyAI maintains formal, auditable management systems and publishes both certificates:
- ISO 27001:2022 — Information Security Management System (ISMS). View ISO 27001:2022 Certificate.
- ISO/IEC 42001:2023 — AI management system. View ISO 42001 Certificate.
Compliance posture
ToothFairyAI is built for regulated industries — local government, financial services, construction and healthcare — and its compliance posture covers the following frameworks:
- GDPR (EU) — GDPR-compliant data processing for European customers, with data residency in the Europe region.
- HIPAA (US healthcare) — HIPAA-compliant for healthcare use cases, with data residency in the Americas region.
- Australian Privacy Act (APPs) — Compliance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), the jurisdiction ToothFairyAI is founded in.
Sovereign by default
Data is sovereign by default: on Serverless, all data is stored by default in the region you choose — Australia, Europe, or the Americas — and it stays in your chosen region unless you move it. Under a custom Enterprise agreement, you can add dedicated hosting on-premise or on your own cloud infrastructure.
Data handling
- Zero data retention — Your data never trains shared models and never leaves your private environment — encrypted and fully yours.
- Data is never used to train AI models — Client data is not used to train AI models or for any other purpose, and is accessible only by your team.
- Encryption at rest and in transit — Robust security measures include encryption of data in transit and at rest, strict access controls and comprehensive audit trails.
- Regional data residency — All your data is stored in your chosen region (Australia, Europe, or Americas) on our secure cloud infrastructure by default.
Model & supply-chain control
- Model-agnostic operation — Bring-your-own-model (BYOM) support means teams face no model-provider lock-in; the platform runs model-agnostically.
- Deployment choice — Hosted (Serverless) in a chosen region, or dedicated/on-premise hosting and hosting in your own cloud under a custom Enterprise agreement.
- Enterprise controls — Enterprise agreements include single sign-on and secure database connections.
Security & Compliance documents
The following trusted references detail ToothFairyAI's security, privacy and compliance posture:
- Privacy Policy — Data protection framework, zero-retention policy and regional data residency.
- Pricing — Pay-per-use intelligence credits from $5; Enterprise agreements billed annually.
- What is ToothFairyAI? — Company facts, certifications and the seven positioning pillars.
- Developers — TF Code, SDKs, CLI, MCP server and REST API.
- Documentation — User Guide — User guides, agent templates, settings and integrations.
- Administrator guide — Workspace security settings — Multi-factor enforcement, regional enforcement and admin controls.
- Administrator guide — Users, roles & single sign-on — User management, role-based access and SSO setup.
- Account security — Multi-factor authentication — Enabling MFA and account security settings.
- API Documentation — Interactive REST API reference for agents, knowledge hubs and conversations.


