Apps
Platform
Solutions
Resources
PricingAboutPartnersTalk to us
Melorite  ›  Platform

Enterprise-grade
protection and security

Melorite is designed for connected business operations, with privacy, information security, and practical controls at the centre of every implementation.

🛡️

SOC-2

Sana meets the AICPA SOC requirements for customer data management.

🇪🇺

GDPR

We fully comply with GDPR and offer several data portability and management tools.

🔏

ISO:27001

Sana meets the international standard for information management security.

🔑

SSO & SCIM

Single Sign-On through trusted providers. Support for SCIM user provisioning to sync user roles and permissions.

🔐

Access & encryption

Users can only access data they are authorized for. AES-256 encryption is used for data at rest, and TLS 1.2 is used for data in transit.

🧯

Operational security

Safeguards against malicious code of the highest standard, as well as confidentiality agreements with staff, customers, and suppliers.

☁️

Flexible deployment options

Sana is a SaaS solution with managed hosting by default and can be deployed on your cloud infrastructure.

🖥️

Server security and monitoring

Sana complies with SOC 2, ISO 27001, and HITRUST. Data stored with 24/7 threat monitoring.

🚫

No foundation model training

Contractual agreements with AI subprocessors prohibit use of customer data to train their models.

Trusted by innovators and industry leaders

“Sana gives us control over the AI, allowing us to choose the material it accesses and tailor its parameters to our specific needs.”

Frequently asked questions

We use an Information Security Management System (ISMS) certified under ISO/IEC 27001 as the basis for all information security measures. The standard provides guidelines and general principles for planning, implementing, maintaining, and improving information security in an organization.
We prevent unauthorized persons from using systems and processes by adhering to the principle of least privilege and using role-based permissions when provisioning access, and utilizing multi-factor authentication for access to systems with highly confidential data. Our data center and cloud infra partners are ISO27001, ISO27017, ISO27018, SOC2 Type II, PCI DSS, and CSA STAR certified.
We adopt appropriate risk management and security risk management controls such as conducting periodic reviews and assessments of risks, monitoring compliance with our policies and procedures, and keeping an up-to-date risk mapping signed off by senior management.
We maintain different systems and methods to protect the IT infrastructure, use active monitoring to ensure antivirus scanners and spam filters are active and updated, install the latest security updates and patches, and ensure all employees take security training at least once a year.
We require that Sanians conduct themselves in a manner consistent with our guidelines regarding confidentiality, business ethics, and professional standards, enter into confidentiality agreements, and acknowledge compliance with Sana's confidentiality and privacy policies.
We use a dedicated training set of internal data to manually and automatically train our ranking algorithm and query rewrite. No customer data is used outside of the isolated tenant unless specifically agreed upon, and no customer data is used to train third-party LLMs.
Data added through integrations and/or through upload to Sana Agents is indexed and stored on our cloud instance.
Sana isolates all customer data using a single tenant architecture, meaning no databases are shared between customers. Data at rest is encrypted with AES 256 and data in transit is encrypted with TLS 1.2+.
There are three ways documents can be added to Sana Agents: direct upload, private integration, and shared integration. Accessibility depends on how the document was added and admin settings — each user can generally only see what they're authorized to see.
Sana Agents is built agnostic to the underlying large language models. Sana offers third-party LLM options which are not trained on Content Data, and utilizes a Zero-Day Retention (ZDR) policy with third parties whenever possible.
You can control which integrations are available to the organization, and which ones feed into the natural language response from Sana Agents.
Sana employees do not have access to your workspace by default, and will only be able to access it if you grant them access by extending an invite. Developers have access to underlying databases only through stringent least-privilege processes and audit trails.