Back to home

Trust & Security

How Saphion protects your data, keeps a named person accountable for every professional decision, and is honest about what isn't built yet.

The principles that govern every product

These aren't aspirations for later — they're the rules Saphion is built to.

Your Organisation is isolated

One customer is one Organisation, with its own tenant-scoped data. Nothing is shared across Organisations by accident or by default.

Least-privilege access

People hold roles — Admin, Member or read-only Viewer — plus any individual permissions granted to them by name. Sensitive actions like sign-off are granted deliberately, never assumed.

Protected finals

Once a competent person signs a document, it's protected. It can't be silently changed — only superseded by a new, tracked version.

Your document, your identity

An issued document carries your branding and house style, never Saphion's. Working-state markings never appear on a signed final.

Human review stays explicit

Saphion AI's proposals are always visible and reviewable before they're adopted — never a silent or automatic change.

Provenance and audit

Lifecycle, approvals and document history are recorded — so who did what, and when, is always traceable.

Built toward recognised standards, honestly labelled.

Saphion doesn't claim certifications, insurance or accreditations it doesn't hold. Where a control is genuinely in place, we say so plainly; where it's still being built, we say that too. Nothing is claimed ahead of the evidence.

Have a specific question about access or data?

Ask us directly — we'd rather answer it honestly than leave you guessing.

Talk to Saphion