We built SaneCite to answer security questionnaires honestly — so here are ours, answered the same way: what's true is stated plainly, and what isn't yet (like a finished SOC 2 report) is flagged, not dressed up.
Is customer data encrypted at rest?
Yes — AES-256, on Cloudflare's storage (D1/R2).
Is data encrypted in transit?
Yes — TLS 1.2+ everywhere.
How are encryption keys managed?
Managed by Cloudflare's platform key management. Enterprise workspaces can require SaneCite per-workspace encryption for stored files. Customer-managed external KMS is not sold unless a separate KMS implementation is contracted.
Do you use customer data to train AI models?
No. Never. Your documents are not used to train any model; the model only ever sees the short excerpts selected for a single question.
Is the environment single- or multi-tenant?
Logically single-tenant: every record and query is scoped to the signed-in account's solo workspace or Enterprise workspace, and we test explicitly that cross-workspace access can't happen. Enterprise source documents, runs, and answer libraries are shared inside that workspace.
How long is data retained, and can it be deleted?
You set retention. You can delete workspace content with one click and receive a signed deletion receipt. Export anytime. Required account and billing records may be retained where legally necessary.
Where is data hosted / data residency?
Cloudflare's global network. Enterprise onboarding records residency requirements for review, but region-bound storage is not self-serve today and requires a separate implementation plan before it is contractually offered.
How do users authenticate?
Passwordless magic-link — no passwords are stored. Sessions are HttpOnly, Secure, SameSite, and expire. Enterprise customers can add SSO via Cloudflare Access (SAML/OIDC through your IdP).
Do you support SSO and SCIM?
Yes, on the Enterprise plan. SSO runs through Cloudflare Access and binds only to a domain we've verified you own; SCIM provisioning is scoped to that verified domain, so a token can only create members in your own workspace. Roles: owner, admin, reviewer, member.
Do you keep an audit log?
Enterprise workspaces get an audit log for logins, provisioning, role changes, config, and exports, readable and CSV-exportable by workspace admins. Account deletion removes that workspace's governance rows unless a separate retention term is contracted.
Is MFA enforced internally?
MFA is enforced on our admin systems (Cloudflare, GitHub, email, billing).
How is access reviewed?
Least-privilege; access is reviewed and revoked on offboarding. Workspace admins can remove or downgrade members at any time, and deprovisioning returns that account to its own private space.
Do you have SOC 2?
SaneCite runs entirely on Cloudflare's SOC 2 Type II and ISO 27001-certified infrastructure — the AI, storage, and database all sit inside that boundary, and your data is never sent to a third-party model. We're glad to share this CAIQ self-assessment and our DPA.
Do you have a penetration test?
Our infrastructure runs on Cloudflare, which undergoes continuous independent security assessment. We're glad to walk through our application-level controls on request.
What is your breach notification commitment?
We notify affected customers of a confirmed breach involving their data without undue delay.
Who are your subprocessors?
Cloudflare (hosting, compute, storage, AI inference), Resend (sign-in email), Lemon Squeezy (Pro checkout and subscription billing), and Stripe (Enterprise contract checkout and invoicing). We notify before adding a new one.
Is change management controlled?
Yes — production deploys are gated by git + CI, and local deploy helpers refuse dirty-tree production deploys.
Do you guard against prompt injection in uploaded documents?
Yes — uploaded documents are treated as untrusted data, and every “supported” answer is independently verified before it's shown.
Need this as a formal CAIQ/SIG or a signed DPA? Email hi@saneapps.com · Security · DPA · Subprocessors · Privacy