Built for counsel. Ready for review.
SOC 2 Type 2. Zero data retention (ZDR) with our model providers. Reports and questionnaires are in the Trust Center.
Controls
What we commit to
The specifics a security review needs are in the Trust Center.
In-house security team
Security sits in product, infrastructure, and operations. Monitoring and incident response run 24/7.
Your data, your control
You set retention. You can export your data when you need it.
No training. ZDR with model providers.
We do not train on your data. Model providers are under zero data retention (ZDR) agreements: they do not retain prompts or outputs.
Access controls
SAML SSO, role-based permissions, audit logs, and user lifecycle management.
Contractual commitments
Security addendum aligned to SOC 2 Type 2. Terms your counsel can review.
Independent testing
Third-party audits and annual penetration tests. Reports are in the Trust Center.
Review
Send this to your security team
SOC 2 Type 2, and zero data retention (ZDR) with our model providers. Reports, questionnaires, and the rest of the review pack are in the Trust Center.
FAQ
From security reviews
Short answers here. The review pack is in the Trust Center.
Encryption at rest (AES-256) and in transit (TLS 1.3), access controls, audit logs, network isolation, and continuous monitoring. Sandstone is SOC 2 Type 2. Reports are in the Trust Center.
SOC 2 Type 2. Additional independent assessments are available in the Trust Center rather than listed here.
No. We do not train models on customer data. Model providers are under zero data retention (ZDR) agreements, so they do not retain prompts or outputs.
Zero data retention applies to our model providers: they process a request and do not keep the prompt or output. Sandstone still stores the data you put in the product so we can run the service.
Role-based access, SAML SSO, and session management. Access is logged.
Continuous automated scanning, internal assessments, and annual third-party penetration tests. Current reports are in the Trust Center.
Have more questions about our security practices?
Contact Security Team


