Evidence & trust
Operant’s security page states SOC 2 Type II compliance and describes mandatory code reviews, vulnerability scanning and patching, RBAC, environment segmentation, MFA on SaaS accounts and a responsible-disclosure channel. These are meaningful transparency signals, but they are provider statements in the material reviewed here rather than an independently inspected audit report. 5
Its Privacy Policy and Terms of Use are both effective December 1, 2023, materially predating the 2026 Semantic Firewall release. The privacy policy describes collection of service and website personal data, use of service providers and analytics partners, security measures and purpose-dependent retention; it does not by itself establish the handling architecture of every current enterprise deployment. Buyers should therefore distinguish general website/service privacy terms from the customer-controlled runtime deployment claims made for Semantic Firewall. 671
Independent context is stronger on company continuity than on product validation. SecurityWeek reported Operant’s $10 million Series A in September 2024, bringing total funding at the time to $13.5 million, and described the company’s runtime-protection positioning while clearly attributing performance claims to Operant. Current launch coverage confirms the Semantic Firewall release and its stated feature set, but does not provide independent security testing. 38
The fixed evidence panel produced no current substantive exact-product source in this cycle. Five panel domains were inaccessible and the remaining source-specific searches produced no relevant exact-product material. That lack of panel coverage is not treated as negative product evidence, but it does keep external validation weak and prevents a rating-confidence upgrade. 3