Encryption
Sapling uses TLS encryption for data in transit and AES-256 encryption for data at rest.
From the start, security has been a top priority at Sapling. This is reflected from the ground up in our infrastructure, systems, and procedures.
Sapling uses TLS encryption for data in transit and AES-256 encryption for data at rest.
Our servers are located in a private network with default deny configuration.
Access to data is restricted and data is only processed on our private networks.
All Sapling employees undergo privacy and security training.
Sapling undergoes annual external vulnerability assessment and penetration testing (VAPT), and is also GDPR compliant and SOC 2 Type II certified. Contact us for detailed reports and documentation.
Sapling also supports customers with HIPAA and PCI compliance requirements.


Customized storage and data retention options and self-hosted deployments. Enterprise accounts include audit logs, role-based access controls (RBAC), and single sign-on.
Sapling runs on Amazon Web Services with multiple monitoring and alerting systems for threats and anomalies.
Please email security@sapling.ai with any other questions or concerns. For vulnerability disclosures, we recommend you first contact us for previously reported disclosures.