Security and trust
SOC 2 Type II
Controls aligned
Certification in process
ISO/IEC 27001
Controls aligned
Certification in process
HIPAA
Safeguards aligned
Assessment in process
Your data
Every client contract includes these commitments.
Who decides
You decide what we process and why. We act on your written instructions.
You are the data controller and Sanoki is the data processor. If an instruction conflicts with the law that governs your contract, we tell you.
Where it lives
Your data is stored on Amazon Web Services in the United States.
We give you prior notice before any change of hosting location, and every transfer follows the law that governs your contract.
Deletion
We delete or return your data within 30 days of the contract ending.
Controls
Control in place and aligned– No matching requirement in that frameworkScheduled Planned, results reported here
| Control | SOC 2 | ISO 27001 | HIPAA |
|---|---|---|---|
| Governance and risk | |||
Risk assessment We assess security risks on a schedule and act on what we find. SOC 2ISO 27001HIPAA Technical detailsWe document each analysis, repeat it after major system changes, and keep a treatment plan for every risk. | |||
Security policies Our security rules are written, approved and reviewed every year. SOC 2ISO 27001HIPAA | |||
Management oversight Company leadership sets security goals and reviews how the program performs. SOC 2ISO 27001 Technical detailsLeadership also assigns security responsibilities across the team. | – | ||
Security program scope Every system that touches your data falls inside our security program. ISO 27001 Technical detailsWe document the program's scope, with a statement of applicability for each control. | – | – | |
Internal audit and management review We audit our own controls and fix what the audit finds. ISO 27001 Technical detailsWe plan the audits in advance, leadership reviews the results, and we track each corrective action. | – | – | |
Legal and regulatory requirements We track the laws and contract terms that apply to your data. ISO 27001 Technical detailsWe keep a register of these requirements and review it when they change. | – | – | |
Fraud risk assessment Our risk review includes fraud. SOC 2 Technical detailsThat covers misuse of access and misuse of data. | – | – | |
System description We document how the service works and where your data flows. SOC 2 Technical detailsWe keep the description current, covering the system's boundaries, components and data flows. | – | – | |
Periodic compliance evaluation We check our safeguards against health data rules on a schedule. HIPAA Technical detailsThe evaluation covers technical and non-technical safeguards, and we repeat it when operations or the environment change. | – | – | |
Sanctions policy Anyone at Sanoki who breaks a security rule faces disciplinary action. SOC 2ISO 27001HIPAA Technical detailsThe disciplinary process is written down and covers security and data protection policies. | |||
Security documentation retention We keep security records for at least six years. HIPAA Technical detailsThis covers policies, procedures and required security records. | – | – | |
Business associate agreement We sign a business associate agreement when HIPAA applies. HIPAA Technical detailsThe agreement defines safeguards, permitted uses and breach reporting for protected health information. | – | – | |
| Access and identity | |||
Role-based access Each person reaches only the data their role requires. SOC 2ISO 27001HIPAA Technical detailsEvery person has an individual account, and we grant access on need to know. | |||
Multi-factor authentication Every login to a system that holds your data asks for a second factor. SOC 2ISO 27001HIPAA Technical detailsThis includes administrative access. | |||
Access reviews and offboarding We review who has access and remove it the day someone leaves or changes role. SOC 2ISO 27001HIPAA | |||
Background checks People with access to your data pass a background check. SOC 2ISO 27001HIPAA | |||
Automatic logoff Idle sessions close on their own. HIPAA Technical detailsSessions on systems that hold your data end after a defined period of inactivity. | – | – | |
Emergency access procedure A written procedure lets authorized people reach critical data in an emergency. HIPAA Technical detailsThe procedure limits access to the data the emergency requires. | – | – | |
AI agent permissions An AI agent sees only what the person running it can see. SOC 2ISO 27001HIPAA Technical detailsAn agent working a case inherits the permissions of the person who runs it. You decide who sees each object and each link. | |||
| Data protection | |||
Encryption in transit Your data is encrypted while it travels. SOC 2ISO 27001HIPAA Technical detailsEvery connection that carries your data uses TLS 1.3 or higher. | |||
Encryption at rest Your data is encrypted where it is stored. SOC 2ISO 27001HIPAA Technical detailsWe use AES-256 encryption. | |||
Key and secrets management Encryption keys and credentials live in restricted, managed stores. SOC 2ISO 27001 Technical detailsWe keep them apart from code and rotate them periodically. | – | ||
Client separation Your data sits in its own environment. SOC 2ISO 27001HIPAA Technical detailsNetwork segmentation and logical separation isolate your environment from every other client's. | |||
Data minimization We process only the data your service needs. SOC 2ISO 27001HIPAA Technical detailsWhen anonymized, pseudonymized or aggregated data is enough for the purpose, we use that version. | |||
Data used for your service Models trained on your data serve only you. SOC 2ISO 27001HIPAA Technical detailsThis holds even after anonymization or aggregation. We never sell your data or use it for our own purposes. | |||
Deletion or return We delete or return your data within 30 days of the contract ending. SOC 2ISO 27001HIPAA Technical detailsWe certify the deletion in writing. We erase backup copies on their regular rotation cycle and protect them until then. | |||
| Monitoring and traceability | |||
Audit log We record every access, change and export of your data and keep the log for at least 12 months. SOC 2ISO 27001HIPAA Technical detailsThe log covers all personal data. | |||
Monitoring and alerting We monitor our systems continuously and alert the team to unusual activity. SOC 2ISO 27001HIPAA Technical detailsMonitoring covers systems and logs, and the team reviews the alerts. | |||
Review ledger Every review records who decided, on which evidence, and when. SOC 2ISO 27001HIPAA | |||
Source traceability Every value traces back to the document it came from. SOC 2ISO 27001HIPAA | |||
| Infrastructure and operations | |||
Physical security Our servers run in Amazon Web Services data centers with controlled access. SOC 2ISO 27001HIPAA Technical detailsAmazon Web Services provides the physical and environmental controls. | |||
Asset and device management We keep an inventory of our systems and manage every work device. SOC 2ISO 27001HIPAA Technical detailsTeam laptops are managed, encrypted and kept up to date. | |||
Malware protection Every work device runs protection against malicious software. SOC 2ISO 27001HIPAA | |||
Secure development and change management Every product change is reviewed and tested before release. SOC 2ISO 27001 Technical detailsEach change needs code review, testing and approval before it reaches production. Development and production run in separate environments. | – | ||
Penetration testing An independent penetration test is scheduled. ScheduledSOC 2ISO 27001 Technical detailsAfter the first test, we repeat it periodically and track each finding until it is resolved. | Scheduled | Scheduled | – |
Vulnerability management We apply security patches promptly and test our infrastructure on a schedule. SOC 2ISO 27001HIPAA | |||
Backups We back up your data and test that it restores. SOC 2ISO 27001HIPAA | |||
Continuity and recovery The team restores the service after an outage by following a written plan. SOC 2ISO 27001HIPAA Technical detailsThe plan covers business continuity and disaster recovery. | |||
Vendor risk management We review every company that handles data for us. SOC 2ISO 27001HIPAA Technical detailsWe review each sub-processor before we use it and periodically after. Each one appears on this page with its function. | |||
| People | |||
Confidentiality agreements Everyone on the team signs a confidentiality agreement. SOC 2ISO 27001HIPAA Technical detailsThe obligation continues after employment or a contract ends. | |||
Security training The team trains in data protection every year. SOC 2ISO 27001HIPAA | |||
Data protection lead One person at Sanoki is accountable for security and data protection. SOC 2ISO 27001HIPAA | |||
| Incident response | |||
Incident procedure The team handles every security incident with a written procedure. SOC 2ISO 27001HIPAA Technical detailsThe procedure sets steps to contain the incident, limit its effects, prevent a repeat and support your report to the authority. | |||
Client notification If an incident touches your data, we tell you within 72 hours. SOC 2ISO 27001HIPAA Technical detailsThe 72 hours count from detection, and we add detail as the investigation advances. | |||
Local regulations
Each contract follows the law of its jurisdiction. The controls above meet these local rules.
Colombia
United States
Sub-processors
| Company | What it does |
|---|---|
| OpenAI, Inc. | Language model inference |
| Anthropic, PBC | Language model inference |
| Google LLC (Gemini) | Language model inference and data processing |
| Amazon Web Services, Inc. | Compute, storage and databases |
| Clerk, Inc. | Authentication and user sessions |
| PostHog, Inc. | Application observability and usage metrics. Receives no patient data. |
| Slack Technologies, LLC | Team communication and alerts |
Updates
Our controls are in place and aligned with SOC 2, ISO 27001 and HIPAA.
Contact
Security and data protection
Write to [email protected] with security questionnaires and security concerns.
Incidents
If an incident touches your data, we notify your security contact within 72 hours and send updates until it is closed.
Next steps