Sapilon is in private development and preparing for early access. Join the waitlist →

Trust & Security

You own it. No lock-in.

Plain Git, open libraries, native AWS. No lock-in. And the platform that builds it is governed, auditable, and reversible by design.

How we secure the platform

Sapilon's core premise is that AI must be constrained, observable, and reversible. The same discipline applies to how we run the platform itself.

Governed AI

Ownership zones (//!AUTO · //!SAFE · //!DEV) define exactly what the AI may change. Automated review runs on generated changes, and every AI action is logged, diffable, and reversible.

Environment isolation

Projects move through separate Build, Rehearsal, and Live Servers. Nothing reaches a Live Server without passing through the earlier stages, and production data does not flow back into build environments.

Your infrastructure

Generated software deploys to your own AWS account as plain Git repositories on open libraries. Your production workloads and their data stay under your keys and your control.

Encryption

Data is encrypted in transit (TLS) and at rest across platform data stores and backups.

Access control

Role-based access with least privilege for any operational access to customer data, and audit trails on administrative actions. Secrets live in managed secret stores, never in code.

Human escalation

Decisions the AI should not make alone are escalated to you, or to verified independent experts through the marketplace, with published all-inclusive rates.

Where your data goes

Platform data lives in AWS regions in the European Union by default; software you deploy runs in your own AWS account. We use four sub-processors, no more:

Sub-processor Purpose Location & safeguards
AWS Hosting for the platform and customer environments EU (default regions)
Anthropic AI model processing (Claude); no training on customer content US / EU, SCCs
Stripe Payment processing EU / US, SCCs
Google Consent-gated website analytics only EU / US, SCCs

Full terms, notice periods, and objection rights are in the Data Processing Agreement.

Compliance, stated honestly

GDPR

We operate as your GDPR processor for project data, with EU data residency by default, Standard Contractual Clauses for any transfer outside the EU/EEA, and a published DPA that applies to every customer automatically.

ISO 27001

Our security practices are designed to align with ISO 27001. Formal certification is a roadmap item, not a current certificate; this page is updated the moment that changes. We would rather tell you plainly than imply a badge we don't hold.

Responsible disclosure

Found a vulnerability in sapilon.com or the platform? Email we@sapilon.com with "Security report" in the subject. We confirm receipt within 2 business days, keep you informed while we fix it, and credit researchers who report in good faith. Please don't access other customers' data or disrupt the service while testing; good-faith research under this policy will not lead to legal action from us.

Common questions

Do I own the code Sapilon produces?
Yes. Sapilon produces plain Git repositories with open libraries, deployed to your own AWS account. There is no proprietary runtime and no vendor lock-in. You can take the code and leave at any time.
Where does my software run?
In your own AWS account, in AWS regions in the European Union by default, across separate Build, Rehearsal, and Live Server environments with cost visibility built in. Sapilon is AWS-native.
Is the AI safe to trust?
Every AI action is logged, diffable, and reversible. Explicit ownership zones (//!AUTO, //!SAFE, //!DEV) define what the AI may change and what stays under human control, and automated code review runs on generated changes.
Is my code or data used to train AI models?
No. Sapilon does not train models on customer content, and AI processing runs on Anthropic Claude under commercial terms that prohibit training on customer content.
Does Sapilon offer a DPA?
Yes. A GDPR Data Processing Agreement applies to every customer automatically as part of the Terms of Service, covering the processor role, EU data location, sub-processors, breach notification, and deletion. It is published at sapilon.com/dpa.
What about compliance?
Sapilon is designed to align with ISO 27001 and GDPR. Formal certification status is disclosed here as it is achieved: we state what is certified and what is a roadmap item, and never blur the two.