Enterprise-grade security, built-in
Authentication, authorization, and encryption across the stack.
Security architecture
Multiple layers of protection
Auth & Sessions
Supabase Auth with email OTP and magic-link sign-in; server-side session validation on every request
Row-Level Security
Strict access controls on all database tables; users only see their own data and team data
Encryption at Rest
AES-256 encryption for all stored data including conversations and documents
Encryption in Transit
TLS 1.2+ for all connections; HTTPS enforced across the platform
Payment Security
Stripe integration (PCI DSS Level 1); no card data stored in our system
Compliance Posture
Hosted on Supabase and Render, whose platforms carry SOC 2 Type 2 attestations; Soligo LLC is not itself independently audited
Audit & Monitoring
Rollbar error tracking, structured server-side logging, and product analytics
Input Validation
Zod schema validation on all inputs; file type and size restrictions
Edge Protection
Cloudflare edge protection and TLS termination provided by our hosting platform
Data handling
Your data stays secure and under your control
We take data protection seriously. All user data, conversations, and uploaded files are protected by multiple security layers.
Upload controls
- • MIME type restrictions for safety
- • File size limits (10-50MB depending on type)
- • Signed URLs with automatic expiry
- • Access control policies on storage
Data retention
- • Self-serve account deletion in settings
- • Administrator-initiated deletion on request
- • Data hosted in United States regions
- • Conversations retained until deleted by the customer
Admin controls
Roles & Permissions
Granular control over who can do what with role-based access and hierarchical permissions.
- • Superadmin, Admin, and Member roles
- • Edit, View, and Chat permission levels
- • Team-based and individual sharing
- • Usage tier management per user
Sharing Scopes
Control visibility with flexible sharing options from private to public.
- • Private (creator only)
- • Team (all team members)
- • Public (anyone with link)
- • Store (listed in directory)
Compliance posture
What we inherit from our infrastructure, and what we practice
SOC 2 Type 2 infrastructure
Our database, storage, and hosting providers maintain SOC 2 Type 2 attestations. Soligo LLC does not hold its own SOC 2 report.
HIPAA
Soligo is not HIPAA-certified and does not currently sign Business Associate Agreements. Do not put protected health information into the platform.
GDPR practices
We honor access, correction, and deletion requests at privacy@soligo.ai, per our Privacy Policy.
Model training
Customer content is never used to train AI models. We call Anthropic and OpenAI over their commercial APIs, which exclude API traffic from model training.
We describe only the controls we actually operate. Subprocessor documentation and a Data Processing Addendum are available on request.
Questions about security?
Our team is here to help with your security review