Trust & Security
How Saphion protects your data, keeps a named person accountable for every professional decision, and is honest about what isn't built yet.
The principles that govern every product
These aren't aspirations for later — they're the rules Saphion is built to.
Your Organisation is isolated
One customer is one Organisation, with its own tenant-scoped data. Nothing is shared across Organisations by accident or by default.
Least-privilege access
People hold roles — Admin, Member or read-only Viewer — plus any individual permissions granted to them by name. Sensitive actions like sign-off are granted deliberately, never assumed.
Protected finals
Once a competent person signs a document, it's protected. It can't be silently changed — only superseded by a new, tracked version.
Your document, your identity
An issued document carries your branding and house style, never Saphion's. Working-state markings never appear on a signed final.
Human review stays explicit
Saphion AI's proposals are always visible and reviewable before they're adopted — never a silent or automatic change.
Provenance and audit
Lifecycle, approvals and document history are recorded — so who did what, and when, is always traceable.
Built toward recognised standards, honestly labelled.
Saphion doesn't claim certifications, insurance or accreditations it doesn't hold. Where a control is genuinely in place, we say so plainly; where it's still being built, we say that too. Nothing is claimed ahead of the evidence.
Have a specific question about access or data?
Ask us directly — we'd rather answer it honestly than leave you guessing.
Talk to Saphion