Sapilon becomes publicly available on 15 November 2026: 50 days to go. The core goes open source the same day →

Trust & Security

You own it. No lock-in.

Open-source core, plain Git, native AWS. No lock-in. And the platform that builds it is governed, auditable, and reversible by design.

How we secure the platform

Sapilon's core premise is that AI must be constrained, observable, and reversible. The same discipline applies to how we run the platform itself.

Governed AI

Ownership zones (//!AUTO · //!SAFE · //!DEV) define exactly what the AI may change. Automated review runs on generated changes, and every AI action is logged, diffable, and reversible.

Private AI

Every prompt, upload, line of generated code and AI answer is processed by Claude on Amazon Bedrock in EU AWS regions. None of it is shared with the model provider or used to train any model. Amazon Bedrock does not store prompts or answers, and Anthropic, the model's maker, has no access to them.

Environment isolation

Projects move through separate Build, Rehearsal, and Live Servers. Nothing reaches a Live Server without passing through the earlier stages, and production data does not flow back into build environments.

Your infrastructure

Generated software runs on production AWS infrastructure provisioned per project, from plain Git repositories on an open-source web and api platform. Environments are isolated per project and per stage, and you can export the code and run it yourself at any time. Enterprise plans can deploy into your own AWS account on request.

Encryption

Data is encrypted in transit (TLS) and at rest across platform data stores and backups.

Access control

Role-based access with least privilege for any operational access to customer data, and audit trails on administrative actions. Secrets live in managed secret stores, never in code.

Human escalation

Decisions the AI should not make alone are escalated to you, or to verified independent experts through the marketplace, with published all-inclusive rates.

Where your data goes

Platform data and the software you deploy both run on AWS infrastructure. AI runs inside AWS too, so we use three sub-processors, no more:

Sub-processor Purpose Location & safeguards
AWS Hosting for the platform and customer environments, and AI model processing (Claude on Amazon Bedrock); no training on customer content EU (default regions; AI in EU regions only)
Stripe Payment processing EU / US, SCCs
Google Consent-gated website analytics only EU / US, SCCs

Full terms, notice periods, and objection rights are in the Data Processing Agreement.

Compliance, stated honestly

GDPR

We operate as your GDPR processor for project data, with EU data residency by default, Standard Contractual Clauses for any transfer outside the EU/EEA, and a published DPA that applies to every customer automatically.

ISO 27001

Our security practices are designed to align with ISO 27001. Formal certification is a roadmap item, not a current certificate; this page is updated the moment that changes. We would rather tell you plainly than imply a badge we don't hold.

Responsible disclosure

Found a vulnerability in sapilon.com or the platform? Email we@sapilon.com with "Security report" in the subject. We confirm receipt within 2 business days, keep you informed while we fix it, and credit researchers who report in good faith. Please don't access other customers' data or disrupt the service while testing; good-faith research under this policy will not lead to legal action from us.

Common questions

Do I own the code Sapilon produces?
Yes. Sapilon produces plain Git repositories on an open-source web and api platform, running on standard AWS services. There is no proprietary runtime and no vendor lock-in. You can export the code and leave at any time.
Is Sapilon open source?
The core is. The web and api platform every Sapilon project is built on is open source, so the foundation of your software is code you can read, fork, and run without Sapilon. The governed agent, the servers, and the experts are the paid service around it.
Where does my software run?
On production AWS infrastructure Sapilon provisions and runs for your project, across separate Build, Rehearsal, and Live Server environments with cost visibility built in. Sapilon is AWS-native, and Enterprise plans can deploy into your own AWS account on request.
Is the AI safe to trust?
Every AI action is logged, diffable, and reversible. Explicit ownership zones (//!AUTO, //!SAFE, //!DEV) define what the AI may change and what stays under human control, and automated code review runs on generated changes.
Is my code or data used to train AI models?
No. Sapilon does not train models on customer content, and none of your content is shared with the model provider: all AI processing runs on Claude through Amazon Bedrock in EU AWS regions, where Bedrock does not store prompts or answers and does not use them for training.
Is my data shared with AI providers?
No. Every prompt, upload, line of generated code and AI answer is processed by Claude on Amazon Bedrock in EU AWS regions. None of it is shared with the model provider or used to train any model. Sapilon runs AI in the EU under the GDPR, with AWS as the processor and no other party in the chain.
Does Sapilon offer a DPA?
Yes. A GDPR Data Processing Agreement applies to every customer automatically as part of the Terms of Service, covering the processor role, EU data location, sub-processors, breach notification, and deletion. It is published at sapilon.com/dpa.
What about compliance?
Sapilon is designed to align with ISO 27001 and GDPR. Formal certification status is disclosed here as it is achieved: we state what is certified and what is a roadmap item, and never blur the two.