Security you can take to procurement.
SOC 2 Type II, VAPT A+ and CMMC Level 1, hosted in US cloud regions. You own your data, it never trains a model, and the reports your security team asks for go out the same day.
- SOC 2
- Type II, audited annually
- A+
- VAPT penetration test rating
- US only
- Cloud regions for customer data
- 0
- of your data used to train our models
Written to be checked, not to reassure.
Primes, agencies and SLED offices set a security bar before a vendor gets near their data. A tool that cannot clear it does not get bought, however good it is.
The bar rises with the size of the buyer. A small business can adopt software on a card. An enterprise capture team cannot, because the same tool has to survive an IT security review, a legal review of who owns the pipeline data, and a supply-chain review by whichever prime they are teaming with this quarter. Those three reviewers want different documents and none of them wants adjectives.
So everything below is one of three things: an attestation an independent party issued, a clause you can read for yourself in our Terms of Service or Privacy Policy, or a plain statement that we do not hold something yet. Where the marketing copy and the contract disagreed, we changed the marketing copy.
Independently verified
Issued by third parties who tested our systems, not asserted by us. Reports available under NDA from support@samsearch.co.
- Independent CPA audit · annual
SOC 2 Type II
Security, availability and confidentiality controls tested across an audit period rather than checked on a single day. The report enterprise IT and legal ask for by name, available under NDA.
- Level 1 self-assessed · Level 2 underway
CMMC Level 2 (in progress)
Level 1 is held today, self-assessed against the 15 basic requirements in FAR 52.204-21 for safeguarding Federal Contract Information. Level 2, which covers CUI, is in progress and not yet held.
- Application · API · infrastructure
VAPT, A+ rating
Penetration tested by LTS Data Point across the web application, the public APIs and the infrastructure underneath them. Zero critical and zero high-severity findings at certification.
- ToU 7B · contractual, not configurable
Your data never trains a model
Client Data and Output Data are never used to train our models or algorithms. Your library grounds your own drafts and nothing else, and it is never sold.
- US regions only
Hosted in the United States
US cloud regions, with production isolated from staging and development and automated backups. Customer data does not leave them.
- SAML 2.0 · your identity provider
Single sign-on
Accounts provision and deprovision through your own IdP, with role-based permissions, enforced MFA and quarterly reviews of every seat that can reach production.
Who owns what
Section 7B of the Terms of Service, in plain language. This is usually the first question your counsel asks and the last one a vendor page answers.
| Category | Owned by | What that means |
|---|---|---|
| Client Data | You | Anything you input, upload or provide to the Service. You own it. We hold a limited licence to use, process and store it for one purpose: providing and operating the Service. |
| Output Data | You | Reports, insights, predictions and drafts generated from your Client Data. You retain full rights, including to everything the AI writes for you. |
| Usage data and metadata | SamSearch | Logs, performance data and how the Service is used. We own this and use it to operate, secure and improve the platform. It is not your pipeline or your documents. |
| Aggregated and anonymised data | SamSearch | Derived data that cannot identify you or your organisation, used for analytics and product improvement. |
| Model training data | Nobody | Your Client Data and Output Data are never used to train our models or algorithms. Not ours, not a shared one, not for machine learning improvement. |
The row worth pausing on is the third. Plenty of vendor pages say “your data is yours” and quietly mean the documents only. Ours says which parts are not: logs, performance data and how the product is used belong to us, and we use them to run and secure the platform. Your pipeline, your documents and everything the AI writes from them are yours.
How the AI is governed
The question every enterprise security review now opens with, and the clause that answers it.
SamSearch is an AI product, so the honest version of this answer matters more than the reassuring one. Terms of Service 7B: we do not use your Client Data or Output Data to train our AI models or algorithms. The Privacy Policy says the same for personal information, content and generated outputs. Neither is a setting someone could switch on for a bigger plan, and retrieval is scoped to your workspace, so when SamSearch drafts against your past performance it is reading your library and nobody else's.
The second half of AI governance is the part vendors tend to leave out. Section 7 of our Terms requires you to review all generated Content before submission or use, and states plainly that outputs are informational assistance rather than legal, accounting or tax advice. A human signs off before anything reaches a contracting officer. That is not a disclaimer bolted on afterwards; it is how the product is designed to be used, and putting it in the contract is what makes it real.
No training, contractually
ToU 7B and the Privacy Policy both prohibit using your data or its outputs to train models. Not configurable, not tier-dependent.
No pooling across customers
Retrieval is scoped to your workspace. Your library grounds your drafts and nobody else's.
Human sign-off required
ToU 7 requires review before submission. We do not warrant AI output for any particular purpose, and we say so in the contract.
Platform controls
The specification behind the summary above. Nothing here is a restatement of it.
| Area | Control |
|---|---|
| Encryption | AES-256 at rest and TLS 1.2 or higher in transit, with additional encryption layers on sensitive fields. |
| Hosting | United States cloud regions. Customer data does not leave them. |
| Environment isolation | Production is fully separated from staging and development. Neither carries customer data. |
| Identity | SAML 2.0 single sign-on through your own identity provider, so joiners and leavers are handled by your IT team rather than by a support ticket to us. |
| Authorisation | Role-based access control, least privilege by default, and MFA enforced across every internal system that can reach production. |
| Personnel access | Only authorised personnel may access customer data, under strict confidentiality obligations. Every seat with production access is reviewed quarterly. |
| Vulnerability management | Regular vulnerability scanning and patching, plus dependency scanning on every deploy rather than on a monthly cadence. |
| Penetration testing | Independent testing by LTS Data Point across the application, the public APIs and the infrastructure. A+ rated, zero critical or high findings at certification. |
| Incident response | A documented and tested plan. Summary shared on request, full plan under NDA. |
| Backups and availability | Automated backups. ToU 20A sets a 99% monthly uptime target for the core Service; it is a target, and credits exist only where a separate enterprise agreement says so. |
Frameworks, and where we actually stand
Including the rows that say no. A reviewer finds those eventually, and it is better they find them here.
| Framework | What it covers | Status | Detail |
|---|---|---|---|
| SOC 2 Type II | Security, availability and confidentiality controls, tested across an audit period | Held | Independent CPA firm. Report under NDA. |
| VAPT | Penetration testing of the application, APIs and infrastructure | Held, A+ | LTS Data Point. Zero critical or high findings at certification. |
| FAR 52.204-21 | The 15 basic safeguarding requirements for Federal Contract Information | Aligned | The control set underneath CMMC Level 1. |
| CMMC Level 1 | Safeguarding Federal Contract Information (FCI) | Self-assessed | Level 1 is self-assessment by design under the CMMC rule. |
| CMMC Level 2 | Safeguarding Controlled Unclassified Information (CUI), on NIST SP 800-171 | Not held, in progress | Controls are being built to the Level 2 requirements. No assessment date to publish yet. |
| FedRAMP High | Authorisation of a cloud service for use by federal agencies | Inherited, not held | The US cloud infrastructure we run on is FedRAMP High authorized. That authorisation belongs to the provider and covers the infrastructure layer. SamSearch itself is not FedRAMP authorized. |
SamSearch runs on US cloud infrastructure that holds FedRAMP High authorization at the infrastructure layer. That authorization belongs to the provider; SamSearch itself is not FedRAMP or StateRAMP authorized, and does not hold ISO 27001. If your programme requires an authorized system of record, say so early and we will tell you plainly whether we fit.
For your vendor security review
What we send, and how fast. Most reviews close on the SOC 2 report alone.
SOC 2 Type II report
The full report, including the auditor's opinion and the tested control set. Sent under NDA.
Penetration test report
The LTS Data Point VAPT report covering the application, APIs and infrastructure. Sent under NDA.
CMMC Level 1 self-assessment
Our scoring against the FAR 52.204-21 safeguarding requirements, and the scope it applies to.
Architecture and data flow
Where customer data is stored, what touches it, and which regions it stays in. Written for a reviewer, not a developer.
Security questionnaire
We complete your standard questionnaire rather than sending ours back. CAIQ, SIG Lite, or a prime's own form.
Incident response plan
Documented and tested. Summary shared on request; the full plan under NDA.
Send your request to support@samsearch.co and we respond the same business day. If you would rather self-serve, the Trust Center carries our current posture without an NDA in the way. Confidentiality runs both ways before you have signed anything: Terms of Service 7A is a mutual clause covering your client data and business plans as well as our technology and pricing, and it survives termination.
Security and legal questions we get asked
In the words they get asked in, answered from the Terms of Service and the Privacy Policy rather than around them.
Is SamSearch SOC 2 compliant?
Do you train AI models on our data?
Who owns the data and the AI outputs?
Where is our data hosted?
Is SamSearch CMMC certified?
Are you FedRAMP authorized?
What is your uptime SLA?
Do you sign an NDA, or is confidentiality already covered?
Who else can see our data?
Do you support SAML single sign-on?
Has SamSearch been penetration tested?
How long do you keep our data, and can we get it deleted?
Can we rely on AI-generated proposal content without reviewing it?
Can you complete our vendor security questionnaire?
What happens to our data and our subscription if we cancel?
Who are we actually contracting with?
How will we know if your terms or privacy policy change?
Enterprise-ready. Procurement-approved.
Request the SOC 2 Type II report, the penetration test, or our CMMC Level 1 self-assessment. Same-day response.
SamSearch is operated by Yeul Payments Inc., doing business as SamSearch. Full terms in our Privacy Policy and Terms of Use. Hosted in the United States. Last reviewed: June 2026.