Secure by design.
Trusted at scale.

We query your systems read-only and in place — no training, no writes, no bulk export.

Data protection

Your data stays yours.

Read-only, in place

Sapien queries connected systems in place, using only the access you grant. Your source records stay unchanged.

No model training

Our enterprise agreements with OpenAI, Anthropic, and Google prohibit using customer data to train their models. Data shared with models to answer your questions remains covered by those agreements.

Encryption throughout

Data is encrypted in transit and at rest. Connection credentials are held in encrypted vaults and accessed by authorized services at runtime.

Organization isolation

Your organization has its own subdomain, encryption keys, and access controls. Organization-level restrictions keep your data, files, and work separate.

Access and identity

You set the boundaries.

Your identity provider

Connect your identity provider through SSO with support for Okta, Microsoft Entra ID, and Google Workspace. Apply your existing MFA policies and manage access through roles and permissions.

Your connections

You provision the service accounts, control access to connected systems, and own the integration lifecycle.

Monitoring and accountability

Visibility into every step.

Ongoing protection

Automated vulnerability scanning and security monitoring help identify threats and suspicious activity. Penetration testing and documented incident response procedures support ongoing protection.

Traceable activity

Execution logs record the sources accessed, tools used, and calculations performed, with timestamps and user attribution to support security reviews and investigations.

Independent assurance

Built for your security review.

AICPA SOC 2

SOC 2 Type II

AICPA SOC 3

SOC 3

SOC 2 Type II and SOC 3 reports document our controls for security, availability, and confidentiality.

HIPAA-related requirements

Aligned controls and practices, with Business Associate Agreements available for qualifying customers.

Enterprise agreements

GDPR-aligned Data Processing Agreements and custom security addenda are available for enterprise deployments.

Frequently asked questions

See what Sapien
can do on your data