Security

Secure by design.
Trusted at scale.

SOC 2 Type II and SOC 3 certified. We query your systems read-only and in place — no training, no writes, no bulk export.

AICPA SOC 2
SOC 2 Type II
AICPA SOC 3
SOC 3 Type II

Security and Trust

Built with security at our core. Trusted by Fortune 500s.

Read-only, query-in-place

Least-privilege access, queried on demand over TLS. No ETL, no writes, no bulk export. If the service account can’t see a table, neither can we.

Isolation and RBAC

Each organization gets its own subdomain and encryption keys, and every query carries an organization filter. A user without access will not see it in search, agent answers, exports, or the UI.

No training on your data

This is contractual, not a policy. Our enterprise agreements with OpenAI, Anthropic, and Google all prohibit training on customer data.

Certifications

SOC 2 Type II and SOC 3, current, covering Security, Availability, and Confidentiality. HIPAA and GDPR aligned, with BAAs and DPAs available.

Auditability

Every agent run is traced: which sources it touched, which tools it ran, which models it called, and how the numbers were produced.

How we handle your data

Read-only. Isolated. Auditable.

We query your systems of record in place. We don’t train on your data, write to your systems, or bulk-copy your data out.

Data access

Read-only, query-in-place

A least-privilege service account. Queries run on demand over TLS. There are no ETL pipelines, no writes, and no bulk exports.

Encrypted credentials

Credentials sit in an encrypted vault and are only decrypted at runtime. If the service account can’t see a table, neither can we.

Isolation

Isolated by organization

Each organization gets its own subdomain and encryption keys. Every database query carries an organization filter.

Authorization on every request

Requests pass through Cloudflare WAF and DDoS protection, then authenticated gateway checks. Authorization runs again on every request.

Monitoring & compliance

Continuous monitoring

Scanning runs around the clock. Penetration tests run quarterly. Anomalies surface to our security team in real time.

Enterprise agreements

DPAs, BAAs, and custom security addenda. The SOC 2 Type II report is available under NDA.

Independently audited

AICPA SOC 2

SOC 2 Type II

AICPA SOC 3

SOC 3 Type II

Questions

Security FAQ

See it on your data

We don’t demo on synthetic data. Book a call and we’ll walk through Sapien live on your numbers — and answer anything your security team needs.

Book a Demo

SOC 2 Type II report available under NDA