Enterprise Security

Enterprise-grade security built into every layer — so your supply chain data stays yours.

How we protect your data

Multiple independent security layers across every surface of the platform.

Data Encryption

  • TLS 1.3 in transit — HTTPS enforced everywhere
  • Enterprise-grade encryption at rest for all files and records
  • Backup data encrypted across secure cloud infrastructure

Access Control

  • MFA available for all accounts
  • Principle of least privilege enforced at infrastructure level
  • Automatic session timeout and strong password requirements

Data Isolation

  • Your data is completely isolated from other users
  • Every file, analysis, and conversation tied to your unique user ID
  • Database rules enforce strict user ownership at the infrastructure layer
  • Separate storage paths per user — no cross-user access possible

Monitoring & Logging

  • 24/7 automated threat detection and alerting
  • DDoS protection, WAF rules, and rate limiting

Your data, your control

All AI processing happens inside our secure infrastructure — never shared, never sold, never used for training.

AI processing happens within our secure, controlled cloud environment
Processed in isolated compute environments
Data residency: United States by default, configurable for enterprise
We don't sell your data to third parties
We don't use your data to train AI models
We don't share your data with other customers
We don't access your data without explicit permission

Security for every plan

Strong defaults for all users, with advanced controls for Pro and Enterprise.

All Users

  • Encrypted data transmission (TLS 1.3)
  • Secure authentication
  • Automatic session timeout
  • Password strength requirements
  • Email verification
Pro & Enterprise

Advanced Controls

  • Multi-factor authentication (MFA)
  • Dedicated security support
  • Security incident notifications
  • Custom data processing agreements
  • On-premise deployment (Enterprise)

Data retention & deletion

Clear policies so you always know what we hold and how to remove it.

How long we keep data

Uploaded filesMax 24 hours
Analysis resultsWhile account is active
ConversationsWhile account is active
Hard-deleted dataRemoved immediately

Your control

You can delete your data at any time — no lock-in, no friction.

  • Delete individual files and analyses
  • Clear your entire conversation history
  • Export all data before deletion (GDPR right)
  • Full account deletion on request

How we respond to incidents

A structured 6-step process ensures rapid containment, transparent communication, and lasting remediation.

01
Detection
Automated monitoring detects anomalies within minutes
02
Response
Security team responds immediately, 24/7
03
Containment
Affected systems isolated within 1 hour
04
Notification
Affected users notified within 72 hours (GDPR)
05
Resolution
Root cause analysis and full remediation
06
Prevention
Security improvements implemented and documented

Third-party service security

Every partner is vetted against enterprise security standards before integration.

Service TypePurposeSecurity Standard
Cloud InfrastructureHosting & computeEnterprise-grade security
AuthenticationUser identityIndustry-standard protocols
DatabaseData storageEncrypted, managed service
Payment ProcessingSubscriptionsPCI DSS Level 1 (Stripe)
Email DeliveryNotificationsSecure, managed service

Compliance & privacy

Built to meet global regulatory requirements from day one.

GDPR
European Data Protection
  • Right to access your data
  • Right to delete your data
  • Right to data portability
  • Transparent data processing
SOC 2
Coming Soon
Security & Availability
  • Security & availability controls
  • Independent third-party audit
  • Continuous compliance monitoring
PCI DSS
Payment Security (via Stripe)
  • Level 1 compliant processing
  • No credit card data stored
  • All payment data tokenized

Continuous improvement

Security is not a one-time effort — it's an ongoing practice.

MonthlySecurity patch updates
QuarterlySecurity training for team
Bi-annuallyThird-party security audits
AnnuallyPenetration testing
OngoingThreat monitoring and response

Questions about security?

If you have specific security requirements or questions not covered here, our team is ready to help.

General Security
security@scmsensei.ai
Response within 24 hours
Enterprise Security
enterprise@scmsensei.ai
Custom security reviews available
Privacy
privacy@scmsensei.ai
GDPR, CCPA, data requests

Last updated: May 2026 · v1.0