Sapling Logo
Security and privacy

Sapling’s Commitment to Security & Privacy

From the start, security has been a top priority at Sapling. This is reflected from the ground up in our infrastructure, systems, and procedures.

SOC 2 Type II GDPR HIPAA support PCI support Annual VAPT
Security by design

Data Policies and Procedures

Encryption

Sapling uses TLS encryption for data in transit and AES-256 encryption for data at rest.

Isolated networks

Our servers are located in a private network with default deny configuration.

Restricted access

Access to data is restricted and data is only processed on our private networks.

Security training

All Sapling employees undergo privacy and security training.

Compliance and assurance

Compliance

Sapling undergoes annual external vulnerability assessment and penetration testing (VAPT), and is also GDPR compliant and SOC 2 Type II certified. Contact us for detailed reports and documentation.

Sapling also supports customers with HIPAA and PCI compliance requirements.

SOC 2
VSA Questionnaire
PCI DSS
HIPAA
GDPR
Single Sign-On
Enterprise controls

Offerings and Infrastructure

Offerings

Customized storage and data retention options and self-hosted deployments. Enterprise accounts include audit logs, role-based access controls (RBAC), and single sign-on.

Infrastructure

Sapling runs on Amazon Web Services with multiple monitoring and alerting systems for threats and anomalies.

Have a security question?

Please email security@sapling.ai with any other questions or concerns. For vulnerability disclosures, we recommend you first contact us for previously reported disclosures.