Security FAQ
Comprehensive answers to security, compliance, and data protection questions about Sana
Is my data secure when using Sana?
Yes. Sana uses AES-256 encryption for data at rest and TLS 1.2 or higher for data in transit. This means your data is protected from unauthorized access both when stored on Sana's servers and when transmitted over networks. Sana isolates all customer data using a single tenant architecture, meaning no databases are shared between customers. Additionally, Sana ensures personal data cannot be read, copied, altered, or deleted by unauthorized persons during transmission, transport, or storage.
How does Sana protect personal data?
Sana protects personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Sana operates as a data processor on your behalf and complies with all applicable data protection laws including GDPR and CCPA. Sana employs multiple data processing systems with different security measures for different purposes to ensure comprehensive protection.
Is my data used to train AI models?
No. Customer content data is not used outside of the isolated tenant unless specifically agreed upon. Sana's default model options are not trained on content data. Your data remains strictly within your environment and is never used to improve third-party language models without your explicit permission.
Does Sana use my data for any other purposes?
Sana uses user interaction data minimally and only to improve service quality and ranking. Sana uses a dedicated training set of internal data to train ranking algorithms and query rewrite to find the most relevant matches. This means Sana improves its search capabilities using Sana's own internal data, not your customer data. Your data is never used for training purposes without your knowledge and consent.
How are Sana employees restricted from accessing my data?
Sana employees do not have access to your workspace by default and can only access it if you explicitly grant them access. Additionally, Sana requires all personnel to enter into confidentiality agreements and acknowledge compliance with confidentiality and privacy policies. This creates multiple layers of protection against unauthorized employee access to your data.
Need more information?
For detailed security documentation, visit sanalabs.com/legal or contact legal@sanalabs.com