We build compliance software, so we hold ourselves to the standard we help our customers meet. This page summarises how we protect customer data. For contractual commitments, see our Terms of Service and Data Processing Agreement.
Our information security management system is built to ISO/IEC 27001, and we are undergoing certification with an independent, accredited certification body. Certificates are available on request as they are issued.
SAMMY runs on AWS, Supabase, and Vercel, hosted in the region that matches you: US regions for US customers, EU-West for EU customers, and the UK for UK customers. Production and development environments are segregated, and customer environments are logically isolated.
Engines are configured and validated using synthetic sample data. The only personal data we routinely hold is the first names and work email addresses of our customers' users.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
Access to customer data is limited to personnel who need it to operate the service, enforced with SSO and multi-factor authentication, and logged.
Model inference is provided by Anthropic as a listed subprocessor. Customer data is not used to train models made available to other customers.
The full list of third parties that process customer data, and what each does, is at sammylabs.com/subprocessors. We give customers notice before adding or replacing subprocessors.
We maintain a tested incident response process. Customers affected by a personal data breach are notified without undue delay, as committed in our DPA.
Data is backed up with defined retention, and restores are periodically tested.
Email security@sammylabs.com. We investigate all good-faith reports and won't pursue action against good-faith security research.
security@sammylabs.com for security, privacy@sammylabs.com for data protection.