Security assurance
Review current security controls and the certification roadmap.
Review details →A single public entry point for how SafeGora protects customer data, where it lives, which vendors process it, and how to request procurement materials. Review the current controls, available documents, and work in progress.
The platform is designed to support regulated workflows, secure data isolation, and enterprise review without forcing teams back into binders, screenshots, and spreadsheet handoffs.
Review what is available today and discuss the requirements that matter to your organization.
Review current security controls and the certification roadmap.
Review details →Review the current accessibility posture and the available request process.
Review details →Discuss the specific connections and supported workflows your team needs.
Review details →Primary application infrastructure (Cloud Run, Cloud SQL, primary filing artifact storage) operates in Google Cloud us-west1 (United States). Multi-region customer-data fan-out is not a product feature today. AI embeddings use Vertex AI; text inference currently uses Google's Generative Language API, with a planned migration to Vertex customer-managed terms that is not complete. Full declaration details and AI endpoint honesty are summarized on /security (Data residency). Procurement teams may request the internal residency declaration via Ollie@safegora.com.
Enterprise customers execute a Data Processing Addendum with their agreement. /legal/dpa describes that process — it is not a signed contract, and a public fill-in-the-blank template is not published there. Request an executable copy or submit redlines at Ollie@safegora.com.
SafeGora uses a small set of sub-processors (cloud infrastructure, identity, billing, communications). The authoritative public list — including categories of personal data processed, processing location, and a 30-day change-notification commitment — is at /legal/subprocessors.
Customer support prefers guided screen-share without operator impersonation. When tenant impersonation is required, it is limited to platform operators on a company email domain, rate-limited, and written to a platform audit log (start/stop events). Break-glass infrastructure access (cloud console / database / secret manager) is reserved for named production owners during severity-1 recovery and follows a two-person process. Support access is least-privilege and ticketed — not unrestricted production access for all engineers.
Buyers in active procurement can request the support-access / break-glass procedure summary under NDA by emailing Ollie@safegora.com.
We welcome good-faith reports from security researchers. Send findings to Ollie@safegora.com. Our machine-readable contact is at /.well-known/security.txt (RFC 9116). We follow a 90-day coordinated disclosure window from initial triage. Full researcher guidelines live on /security.
SafeGora's AI is governed by design, and the controls are product behavior, not policy prose. A person controls the record: AI output is a draft until a named person reviews and approves it — nothing AI-generated becomes the record on its own. Citations are verified: regulatory citations are checked against the jurisdiction's regulation text, and anything that cannot be verified is flagged for human review rather than presented as authoritative. Disclosure by default: AI surfaces identify themselves, AI-assisted drafts are labeled as pending review, and approved records carry a reviewed-and-approved attribution. The full control set, including fallback behavior when verification is unavailable, is documented on the AI governance page.
SafeGora does not hold a third-party security attestation today. SOC 2 Type II is in progress (Type II target Q3 2026). ISO 27001 evaluation is planned after SOC 2 Type II issuance. ISO/IEC 42001 (AI management systems) evaluation is on the roadmap alongside it, reflecting the AI-governance controls above. HIPAA / BAA is not in scope today. See the certifications roadmap on /security. Do not treat this Trust Center as proof of completed certification.
Third-party attestations are one kind of trust; day-to-day engineering evidence is another. SafeGora runs a continuous verification program over the platform itself: every module claim is backed by machine-generated receipts from real test batteries that re-run in CI, required evidence artifacts are signed under a managed cloud key into a single evidence tree, and workers' comp first-report form packs pass a seven-point deterministic certification gate on every build. Reliability and AI-governance behavior are exercised against the running platform with authenticated probes — not only unit tests — and when a check cannot be satisfied honestly it is recorded as an open item, never marked green.
A point-in-time engineering verification certificate summarizing the currently verified module set (17 modules as of July 2026), with the repository and signed-evidence anchors needed to re-derive it, is available to customers and buyers in procurement via Ollie@safegora.com. It is an engineering evidence artifact, not a third-party attestation, and does not replace the certifications roadmap above.
Enterprise buyers can request a deal-minimum trust packet (security overview, isolation summary, privacy / DPA stance, IR/DR posture, and held-claim fences) via Ollie@safegora.com. Signed legal exhibits and full questionnaire packs are handled case-by-case with Legal and Security — not all artifacts are self-serve public downloads yet.
Security and trust: Ollie@safegora.com. Privacy and data-subject requests: Ollie@safegora.com. Legal and contract: Ollie@safegora.com.