SageAI Build A Chatbot

Trust Center

What this product does with your data, where AI inference runs, and what we do not claim. Every statement here is one we can evidence; where something is not yet true, this page says so rather than omitting it.

Your data

Tenant isolation
Every route, query, job, export and AI tool is tenant-scoped server-side. UI hiding is never treated as authorization.
Credentials you enter
Provider keys, connector credentials and webhook signing secrets are encrypted at rest with a dedicated data-encryption key, separate from the key that signs sessions. They are masked in the interface and never returned to the browser.
Your session
Session tokens are httpOnly cookies. No token is placed in browser storage, and unsafe requests carry a CSRF token.
Transport
TLS everywhere. The product does not serve or accept plaintext HTTP in production.

AI processing

Where inference runs
Each request resolves its effective AI runtime against a signed registry and applies that runtime's data rules. A provider name is never treated as proof of where inference executes.
What we do not yet claim
Production customer data is not approved for AI processing today. No runtime in the current registry permits it, so AI features operate on synthetic and approved-public content only. We would rather say this plainly than imply an approval that does not exist.
Your content is not training data
Tenant content is used to ground answers for that tenant. It is not used to train shared models.
Human authority
AI never writes to a system of record on its own. Material changes are proposed and a person approves them.

Compliance posture

Health information
The product stores no structured patient or provider health fields. A formal HIPAA relationship determination has not been completed, so we make no HIPAA claim. If your use involves protected health information, raise it before onboarding.
Certifications
No external certification is claimed. Where evidence exists it is internal control evidence, and we will say which.
Data residency
Hosting, processing and AI-inference locations are declared per deployment. Ask for the current statement for your tenant rather than assuming a region.

Reporting and contact

To report a security issue, contact your implementation lead or the administrator who provisioned your workspace. Include what you observed and when; please do not include credentials or customer data in the report.

Service status and planned maintenance are published at status.sageaiapps.com.