Senpiper
Talk to us

You decide where your data lives, and who can reach it.

ISO/IEC 27001ISO/IEC 42001SOC 2 Type IIISO/IEC 20000-1ISO 9001CMMI level 3CERT-In VAPT

Three things we do not do

Nothing leaves your network

Models, documents, prompts, embeddings and logs stay where you install them. None of it is sent to an outside provider.

Nobody gets in without a role

Every request is refused unless a role allows it. Roles also decide which individual records a person can open.

We do not train on your data

Your prompts and the answers to them are never used to train or test a model that anyone else uses.

Where your data sits

Everything the system needs runs inside the environment you pick. Nothing calls out to an outside provider, so there is no traffic to inspect and no copy to worry about.

A data centre in your country answers the residency question. It does not answer the jurisdiction question, which depends on who controls the machines. On-premise and private cloud answer both.

How someone gets in

Three gates, in this order. A request that fails any of them is written to the log and goes no further.

01

Your own login

People sign in through the identity provider you already use — ADFS, Google, Okta, or any OAuth2 provider.

02

A second factor

A one-time code by SMS or email, or a fingerprint.

03

Their role decides the rest

What someone can open, edit or export is set by role, department and function. Personal data is hidden from roles that do not need it.

How the data is protected

On the way in and out

Every connection is encrypted with TLS 1.2 or 1.3Access can be limited to your own address ranges, with rate limitsPasswords are stored with PBKDF2 SHA-256 at 200,000+ iterationsLogins use stateless tokens, so there is no session to steal

Once it is stored

Disks are encryptedKeys and credentials are encrypted separately from the dataPersonal data is masked per role, so most people never see itThe OWASP Top 10 is reviewed against each new revision

What each deployment gives you

Pick the row that matches what your security team needs to be able to say.

OptionWhere the data sitsWho holds the keysWho can open it
On-premiseYour own data centreYouYour team only
Private cloudYour tenancy, in your regionYouYour team, plus anyone you grant access to
Senpiper-providedOur infrastructure, in a region you pickSenpiper, under contractYour team, plus named Senpiper engineers

Check it yourself

Every certificate on this page carries its number, and every issuer runs a public register you can search.

You also get a staging environment to test the access rules before go-live, and the audit trail is yours to export whenever you want it.

Our certificates

Certificates confirm the system above. They do not replace it. Each one can be checked with its issuer.

ISO/IEC 42001:2023AI management systemsICI/1118269/25Nov 2025 – Nov 2028
SOC 2 Type IIAll five trust services principlesECI/2508/2158Aug 2025 – Aug 2028
ISO/IEC 27001Information security managementCertificate on requestCurrent
CERT-In VAPTPenetration testing by an empanelled auditorReport on requestAnnual
ISO/IEC 20000-1:2018IT service managementICI/4404981/24Mar 2024 – Mar 2027
CMMI-DEV v2.0Maturity level 3, developmentICI/1117309/25Oct 2025 – Oct 2028
ISO 9001:2015Quality management systemsIN/85212523/0289Mar 2024 – Mar 2027