As we service enterprise clients in the U.S. and internationally, we ensure that we (1) follow the latest security practices, (2) seek external testing and audits, and (3) provide customizable cloud and self-hosted/onprem offerings.
Sapling uses TLS encryption for data in transit and AES-256 encryption for data at rest.
Our servers are located in a private network with default deny configuration.
Access to data is restricted and data is only processed on our private networks.
All Sapling employees undergo privacy and security training.
Please contact us for detailed data policies and procedures.
Sapling undergoes annual external vulnerability assessment and penetration testing (VAPT), and is also GDPR compliant and SOC 2 Type II certified. Contact us for detailed reports and documentation.
Sapling additionally supports customers who require HIPAA and/or PCI compliance.
In addition to following security best practices, Sapling also offers customized storage and data retention options and self-hosted deployments. Enterprise accounts include audit logs, role-based access controls (RBAC), and single sign-on.
Sapling runs its production systems on Amazon Web Services (AWS) with multiple monitoring and alert systems to detect threats and anomalies.
Please email security@sapling.ai
with any other questions or concerns.