Trust & Security
You own it. No lock-in.
Plain Git, open libraries, native AWS. No lock-in. And the platform that builds it is governed, auditable, and reversible by design.
How we secure the platform
Sapilon's core premise is that AI must be constrained, observable, and reversible. The same discipline applies to how we run the platform itself.
Governed AI
Ownership zones (//!AUTO · //!SAFE · //!DEV) define exactly what the AI may change. Automated review runs on generated changes, and every AI action is logged, diffable, and reversible.
Environment isolation
Projects move through separate Build, Rehearsal, and Live Servers. Nothing reaches a Live Server without passing through the earlier stages, and production data does not flow back into build environments.
Your infrastructure
Generated software deploys to your own AWS account as plain Git repositories on open libraries. Your production workloads and their data stay under your keys and your control.
Encryption
Data is encrypted in transit (TLS) and at rest across platform data stores and backups.
Access control
Role-based access with least privilege for any operational access to customer data, and audit trails on administrative actions. Secrets live in managed secret stores, never in code.
Human escalation
Decisions the AI should not make alone are escalated to you, or to verified independent experts through the marketplace, with published all-inclusive rates.
Where your data goes
Platform data lives in AWS regions in the European Union by default; software you deploy runs in your own AWS account. We use four sub-processors, no more:
| Sub-processor | Purpose | Location & safeguards |
|---|---|---|
| AWS | Hosting for the platform and customer environments | EU (default regions) |
| Anthropic | AI model processing (Claude); no training on customer content | US / EU, SCCs |
| Stripe | Payment processing | EU / US, SCCs |
| Consent-gated website analytics only | EU / US, SCCs |
Full terms, notice periods, and objection rights are in the Data Processing Agreement.
Compliance, stated honestly
GDPR
We operate as your GDPR processor for project data, with EU data residency by default, Standard Contractual Clauses for any transfer outside the EU/EEA, and a published DPA that applies to every customer automatically.
ISO 27001
Our security practices are designed to align with ISO 27001. Formal certification is a roadmap item, not a current certificate; this page is updated the moment that changes. We would rather tell you plainly than imply a badge we don't hold.
Responsible disclosure
Found a vulnerability in sapilon.com or the platform? Email we@sapilon.com with "Security report" in the subject. We confirm receipt within 2 business days, keep you informed while we fix it, and credit researchers who report in good faith. Please don't access other customers' data or disrupt the service while testing; good-faith research under this policy will not lead to legal action from us.
Common questions
- Do I own the code Sapilon produces?
- Yes. Sapilon produces plain Git repositories with open libraries, deployed to your own AWS account. There is no proprietary runtime and no vendor lock-in. You can take the code and leave at any time.
- Where does my software run?
- In your own AWS account, in AWS regions in the European Union by default, across separate Build, Rehearsal, and Live Server environments with cost visibility built in. Sapilon is AWS-native.
- Is the AI safe to trust?
- Every AI action is logged, diffable, and reversible. Explicit ownership zones (//!AUTO, //!SAFE, //!DEV) define what the AI may change and what stays under human control, and automated code review runs on generated changes.
- Is my code or data used to train AI models?
- No. Sapilon does not train models on customer content, and AI processing runs on Anthropic Claude under commercial terms that prohibit training on customer content.
- Does Sapilon offer a DPA?
- Yes. A GDPR Data Processing Agreement applies to every customer automatically as part of the Terms of Service, covering the processor role, EU data location, sub-processors, breach notification, and deletion. It is published at sapilon.com/dpa.
- What about compliance?
- Sapilon is designed to align with ISO 27001 and GDPR. Formal certification status is disclosed here as it is achieved: we state what is certified and what is a roadmap item, and never blur the two.