Trust Center

Trust & Security

How SAGARIS protects your data — stated plainly, including what is done, what is in progress, and what is not in place yet. We would rather show you an honest roadmap than a wall of badges.

Last updated · August 2026 · Statements reflect the current state of the platform

Security questionnaires & procurement pack
01

Security posture

Hosting & data location

Runs on Google Cloud Platform (Cloud Run and Cloud SQL PostgreSQL) in the us-east4 region. Infrastructure is managed as code, and secrets live in GCP Secret Manager — never in source control or container images.

Encryption

TLS protects data in transit (HSTS enabled; database connections require TLS). Data at rest uses GCP-managed encryption, and high-value credentials such as OAuth tokens are additionally encrypted with AES-256-GCM at the application layer.

Access control

Google Identity Platform session cookies with company-email confirmation codes, verified with revocation checks that fail closed. Time-based one-time-password multi-factor authentication is available with backup codes, and a workspace administrator can require it of every member; sign-in is step-up gated so an enrolled factor cannot be skipped, including on error. Authorization is an eight-role RBAC model with least-privilege, fail-closed defaults; every data access is scoped to your workspace.

Resilience

Automated database backups with point-in-time recovery and deletion protection. Background work runs on durable job queues. Our published recovery targets are a recovery point objective of five minutes or better and a recovery time objective of four hours or better, with a documented restore procedure. Known open items: the primary database is single-zone today, regional high availability is a tracked infrastructure change, and the restore procedure has been written but not yet rehearsed, so those targets are documented rather than measured.

Secure development

Pull requests route security-sensitive paths to code owners and report build, lint, type-check, test, npm-audit, and govulncheck results. These checks are advisory until branch protection is enabled; the database-migration workflow adds a separate fail-closed apply gate.

Monitoring

Structured logs with automatic redaction of sensitive values, audit trails for exports, imports, and AI-initiated actions, plus uptime checks and alerting on availability, error bursts, latency, and database and platform saturation.

Standards & Compliance

SAGARIS is built with security and privacy at its core, constantly advancing to exceed enterprise best practices.

In progress

SOC 2 Type I

Building toward trusted data handling.

In progress

SOC 2 Type II

Controls being proven over time.

GDPR-ready

Built for enterprise privacy needs.

Coming soon

ISO 27001

Security managed to global standards.

02

What SAGARIS does not do

Six product boundaries, built into the platform and shown to every workspace owner in the product itself.

Does not send outreach without explicit human approval.

Drafts are generated for review. A person confirms each send (or an opt-in auto-send rule) before any message leaves the workspace.

Does not write back to your CRM unless write-back is enabled.

Sync is read-first. CRM write-back is opt-in per object and follows the conflict-resolution matrix below; Sagaris-owned fields never overwrite your reps blind.

Does not extract fields you place on the do-not-extract list.

An excluded field is never read into the model context, even when its parent object is included for extraction.

Does not train shared models on your workspace data.

Your records are used to serve your workspace only. They are not pooled into a cross-customer training set.

Does not delete CRM records on your behalf.

Sagaris creates and updates within the limits you set. Destructive deletes stay a human action in your CRM.

Does not expand its data scope without a configuration change.

What is extracted is governed by the toggle matrix on this page. Adding a new object or field to extraction is always an explicit, logged change.

03

Compliance roadmap

SOC 2Internal control matrix complete, attestation pending
In progress

Full SOC 2-mapped technical control audit completed in July 2026 with a maintained remediation gap register. We do not yet hold a SOC 2 report — engaging a third-party auditor is a planned milestone — and we will not describe ourselves as certified until an independent auditor says so. Reviewers can request the control matrix and gap register.

Penetration testingNot yet conducted
Planned

A third-party penetration test has not yet been performed. Internal security audits (application security, access control, secrets) are complete and available to reviewers on request. When an external test is completed, its summary will be published here.

Enterprise accessSCIM built and gated, SSO on the roadmap
Partial

SCIM 2.0 provisioning is built but gated and not yet generally available. SAML/OIDC single sign-on is on the roadmap and has not been built yet; today, sign-in uses Google Identity Platform with company-email confirmation codes. Contact us if either is a requirement for your evaluation.

04

Data handling commitments

Consent-first outbound: per-contact, per-channel consent tracking with regional rules (GDPR, CAN-SPAM, TCPA, CCPA/CPRA, CASL, PECR) and non-overridable safeguards such as mandatory unsubscribe links and do-not-call screening.

Right to erasure is implemented: personal data is anonymized, hashed suppression records prevent silent re-import, and a verifiable deletion certificate is produced.

Your data is exportable: contact and workspace data can be exported in CSV form, and data-subject-request activity is tracked against statutory deadlines. A dedicated self-service request portal is on our roadmap.

Opt-outs are honored immediately across all sequences for that channel.

05

Subprocessors

A defined set of service providers operate the platform. Several only process data when you enable the relevant feature or integration. A full list with purposes and data categories is available to security reviewers on request.

Cloud & AI infrastructure

Google Cloud Platform (hosting, database, auth), Vertex AI Gemini (primary LLM), OpenAI and Anthropic (optional fallback LLMs)

Communications

Telnyx (telephony/SMS), Twilio (legacy telephony paths), Resend (email delivery), ElevenLabs (voice synthesis)

Business & enrichment

Stripe (billing), Apollo.io (enrichment), Perplexity (research)

Customer-enabled integrations

Salesforce, HubSpot, Gmail/Google Calendar, Microsoft Outlook (Entra ID), LinkedIn, X

Domains & DNS

Cloudflare, GoDaddy, Porkbun

06

Report a vulnerability

We acknowledge reports within 2 business days. Report suspected vulnerabilities privately by email to security@sagaris.ai, never through a public channel.

Email security@sagaris.ai
Book a demo