How we give you that confidence

Your book sits behind layers of protection, and every request crosses each one before it can reach your data. Here's every layer, top to bottom.

  1. Network Boundary
  2. Access & Authentication
  3. Tenant Isolation
  4. Encryption
  5. How It's Stored
  6. Daily Backups
  7. Logging & Audit Trail
  8. Secrets Handling
  9. Independent Audits & Testing

Network Boundary

Before anything reaches us, traffic passes through a global edge network that absorbs denial-of-service attacks and rate-limits abusive requests. The application and API are never exposed directly.

Access & Authentication

We never see your password, and neither does anyone else. Sign-in runs on Amazon's identity service, trusted by thousands of companies, and stores no password a person could read. Sessions time out on their own.

Tenant Isolation

Row-level security walls your data off to your own company inside the database. It's reachable only when it's you asking, and enforced deep enough to hold even if a bug ever slips into the app above it.

Encryption

Every byte is encrypted with AES-256 at rest and TLS in transit, unreadable whether it's sitting still or moving between you and us.

How It's Stored

Your records and your documents sit in professionally run data centers on US soil, the same class of infrastructure the rest of the enterprise software world runs on. Everything is encrypted, fenced off to your company alone, and never mixed in with another customer's book.

Daily Backups

The database is backed up every day, so an earlier version can always be restored. Nothing gets lost internally.

Logging & Audit Trail

Every change writes a permanent event stamped with who, when, and which account. Nothing can be quietly rewritten; voided entries are marked, never deleted.

Secrets Handling

The keys that unlock your data never leave our servers. Nothing hidden in the page in front of you, or in anyone else's, would get a person one step closer to your book. And the app can't be wrapped inside a lookalike site to trick your team into handing over a login.

Independent Audits & Testing

We don't grade our own homework. A SOC 2 Type I audit is scheduled for Q3 2026, with independent penetration testing to follow. Findings feed straight back into the build so gaps get closed, not hidden.

Frequently Asked Questions

Can a competitor see our book?

No. Your data is walled off to your own organization, enforced inside the database itself, so it holds even if a bug slips into the app above it.

  • Even if we shipped a bug tomorrow, the database itself would refuse to hand your data to anyone outside your organization.
  • Your PDFs and uploads have no public web address for anyone to guess at. Every file goes through the same gate that walls off the rest of your data. Ask for a file that isn't yours and the system simply says it doesn't exist.
  • No one can pretend to be signed in as someone from your company.
Can our own salespeople walk out with it?

Sales-role users only see the deals they created or are assigned to, and admin actions are enforced on the server, not the interface.

  • A salesperson can't browse the whole company's deals, only their own.
  • The rules live on the server, so a nosy admin can't unlock a restricted action just by editing the page in their browser.
  • Sessions expire on a rolling window, so long-forgotten browser tabs stop working.
Does your AI read our deals?

No, it can't go looking. The assistant has no direct line into your data. It can only ask our system the same questions you could ask it yourself, and it only ever gets back what you're already allowed to see.

  • When you ask a question, the assistant doesn't go rummaging through your book. It works out which of a short, pre-approved set of questions to put to our system, and shows you what comes back, nothing more.
  • It acts as you. It sees exactly what your own account can see, and nothing from any other company, ever.
  • What you type is never used to train any AI model, ours or anyone else's.
What happens to our data if we leave?

You can export your data today, with a defined export window even if SAMS ever couldn't continue operating.

  • You can request a full export of your account's data today: deals, contacts, documents, and accounting history.
  • When your account winds down, we purge your rows and your documents on request.
  • We don't sell, rent, or share your identifiable trade data, contacts, or documents, and we don't train AI on your book.
Who at SAMS can see our data?

Only when required to resolve something you've raised. Nobody browses customer data casually, and every access leaves a trace.

  • The list of people with credentials to production is short and named, not "the engineering team."
  • Every query into production is logged, with the operator and time.
  • When you file a support case, an engineer looks only at what's needed to resolve it, and nothing more.

Certifications

Framework Status Where it stands
SOC 2 Type I In progress Compliance platform onboarded; Type I audit scheduled Q3 2026.
GDPR / UK GDPR Aligned Signable DPA with Standard Contractual Clauses on request.
CCPA / CPRA Aligned We don't sell or share personal information; access, deletion, and export requests honored.
ISO 27001 Planned Scoped for after SOC 2; controls largely covered by the SOC 2 program.

Sub-processors

Vendor What they touch Region
Cloudflare Edge network, Workers runtime, R2 document storage Global edge / US
Supabase Managed Postgres (primary database) US
AWS Cognito Hosted authentication (login, session tokens) US
Cloudflare Workers AI In-app assistant inference (zero-retention) Global edge
QuickBooks (Intuit) Accounting sync via OAuth US

Contact.

Security questions, questionnaires, and vulnerability disclosures go straight to a real person.