Enterprise-grade security, built-in

Authentication, authorization, and encryption across the stack.

Security architecture

Multiple layers of protection

Auth & Sessions

Supabase Auth with email OTP and magic-link sign-in; server-side session validation on every request

Row-Level Security

Strict access controls on all database tables; users only see their own data and team data

Encryption at Rest

AES-256 encryption for all stored data including conversations and documents

Encryption in Transit

TLS 1.2+ for all connections; HTTPS enforced across the platform

Payment Security

Stripe integration (PCI DSS Level 1); no card data stored in our system

Compliance Posture

Hosted on Supabase and Render, whose platforms carry SOC 2 Type 2 attestations; Soligo LLC is not itself independently audited

Audit & Monitoring

Rollbar error tracking, structured server-side logging, and product analytics

Input Validation

Zod schema validation on all inputs; file type and size restrictions

Edge Protection

Cloudflare edge protection and TLS termination provided by our hosting platform

Data handling

Your data stays secure and under your control

We take data protection seriously. All user data, conversations, and uploaded files are protected by multiple security layers.

Upload controls

  • • MIME type restrictions for safety
  • • File size limits (10-50MB depending on type)
  • • Signed URLs with automatic expiry
  • • Access control policies on storage

Data retention

  • • Self-serve account deletion in settings
  • • Administrator-initiated deletion on request
  • • Data hosted in United States regions
  • • Conversations retained until deleted by the customer

Admin controls

Roles & Permissions

Granular control over who can do what with role-based access and hierarchical permissions.

  • • Superadmin, Admin, and Member roles
  • • Edit, View, and Chat permission levels
  • • Team-based and individual sharing
  • • Usage tier management per user

Sharing Scopes

Control visibility with flexible sharing options from private to public.

  • • Private (creator only)
  • • Team (all team members)
  • • Public (anyone with link)
  • • Store (listed in directory)

Compliance posture

What we inherit from our infrastructure, and what we practice

SOC 2 Type 2 infrastructure

Our database, storage, and hosting providers maintain SOC 2 Type 2 attestations. Soligo LLC does not hold its own SOC 2 report.

HIPAA

Soligo is not HIPAA-certified and does not currently sign Business Associate Agreements. Do not put protected health information into the platform.

GDPR practices

We honor access, correction, and deletion requests at privacy@soligo.ai, per our Privacy Policy.

Model training

Customer content is never used to train AI models. We call Anthropic and OpenAI over their commercial APIs, which exclude API traffic from model training.

We describe only the controls we actually operate. Subprocessor documentation and a Data Processing Addendum are available on request.

Questions about security?

Our team is here to help with your security review