SOC 2 Type I
Sail is SOC 2 Type I compliant. You can request the independent auditor report through our Trust Center.SOC 2 Type II
Sail’s SOC 2 Type II compliance takes effect August 25, 2026.HIPAA and BAAs
Enterprise customers can sign a business associate agreement (BAA) with Sail for HIPAA-regulated workloads.Master services agreements
Enterprise contracts can include a signed master services agreement (MSA).Data processing
Retention depends on the Sail product and the data involved. The inference retention policy below does not apply to Sailbox state and checkpoints or to security and audit records.Inference: Zero Data Retention by default
Sail defaults to zero long-term retention of inference request and response data:- We use inference request and response data only to provide the services you request and follow your documented instructions.
- We do not use inference request or response data to train, fine-tune, or improve models without your written consent.
- We do not sell or share customer personal data from inference requests or responses.
- Inference processing is transient and in memory, apart from temporary storage needed to run a job.
- We automatically delete temporary inference data after processing and do not retain it for longer than 48 hours, subject to the exceptions in the DPA.
- Our public DPA forms part of the self-service terms and written customer agreements.
Sailboxes
Sailboxes are stateful by design:- A Sailbox’s writable disk persists for the life of the Sailbox, including across pause, sleep, resume, migration, and recovery.
- Temporary data used to migrate a Sailbox is retained for no more than 24 hours.
- An explicit checkpoint handle expires after seven days by default, or after the TTL set when the checkpoint is created. Expiry controls how long the handle can start a new Sailbox; it does not set a deletion deadline for data still used by a Sailbox.
Data residency and regional processing
By default, Sail uses service providers in multiple regions, so customer data may be processed or stored outside the United States. Enterprise customers can pin traffic to a specific geographic region; contact support@sailresearch.com to confirm the processing and storage locations available for your workload.Signed DPAs
Enterprise customers can sign a DPA with Sail. Self-service customers are covered by our public Data Processing Agreement.Security controls
Our published controls include:- Encryption of customer data at rest and in transit
- Multi-factor authentication for critical services and regular employee access reviews
- Automated infrastructure security scanning and vulnerability management
- Audit logging, monitoring, and an incident response process
- Tested business continuity and disaster recovery plans