samsearch
    Platform
    01InfluenceShape the requirement before it's on your competitor's radar.
    Signal
    Recompete window opens in 42 days
    Facilities maintenance IDIQ$8.4M
    Forecast
    Agency spend up 18% next FY
    DoD facilitiesQ3 window
    02CaptureFind and qualify the work across every market.
    Federal91%
    Network engineering support — GSA MAS
    GSA541512
    SLED88%
    Custodial services — Fairfax County Public Schools
    K-12561720
    DIBBS79%
    Aircraft hydraulic fitting — DLA Aviation
    DLANSN 5330
    03AnalyzeExtract requirements and build the compliance matrix.
    Compliance matrix
    L.2.1Technical approachVol I
    L.3.4Staffing planVol I
    M.1Past performanceEvaluated
    SOW breakdown
    Requirements extracted38
    Mapped to Section L/M38
    Every extractionCited
    Ask Sammy
    “Do we meet the small business set-aside?”
    04ManageRun the pursuit through to award.
    Pipeline
    QualifyFacilities support · USACE
    CaptureComms upgrade · DLA
    ProposalShipyard dredging · NAVSEA
    PriyaAlex
    This week
    Submit past performance refsThu
    Confirm subK teamingFri
    Upload SF 33Mon
    05RespondDraft and submit your response.
    Drafting · Volume I
    247 words
    RFI response
    CompanyAcme Robotics LLC
    UEIJK4M8…
    Capability narrativeDrafted
    06FinanceGet paid faster on what you win.
    Capital available
    $2.4M against your award
    Facilities maintenance IDIQAwarded
    Partner matched
    LenderFederal Capital Partners
    Draw available$2.4M
    UnderwritingCleared
    The platform
    Influence
    Capture
    Analyze
    Manage
    Respond
    Finance
    One pipeline, six stages, start to award.
    See the whole platform
    Solutions
    By industry
    Tech & softwareSoftware and SaaS companies entering GovCon.Defense contractorsPrimes and subs in the defense industrial base.ConstructionBuilders bidding federal, state, and local work.CybersecuritySecurity vendors pursuing federal mandates.
    By team
    Capture managers & BDPipeline, qualification, and win strategy.Proposal teamsCompliance matrices and proposal drafting.Subcontractors & primesTeaming, subcontracting, and partner fit.
    By company size
    Small businessesSet-aside and small business contractors.EnterpriseLarge contractors running multiple pursuits.ConsultantsAdvisors and capture consultants.
    Browse all industries
    CustomersPricing
    ResourcesNew
    Learn
    AcademyCourses, guides, and playbooks.WebinarsLive sessions and recordings.DocsProduct documentation and setup guides.Implementation planOperational rollout guidance.
    Tools & data
    Free GovCon toolsCalculators, lookups, and more.Gov ExploreContracts, agencies, and NAICS codes.GovCon eventsConferences, training, and set-aside events.
    Latest blogIntroducing the New SamSearch: The Operating System for Government ContractingSamSearch has a new brand, a new site, and a new way of explaining what the platform actually does — the operating system for government contracting, organized around six stages instead of a single search box. Here's what changed and why.Read the post →
    All resources and tools
    Sign inRequest a demo
    1. Home
    2. Compliance
    Security and compliance

    Security you can take to procurement.

    SOC 2 Type II, VAPT A+ and CMMC Level 1, hosted in US cloud regions. You own your data, it never trains a model, and the reports your security team asks for go out the same day.

    Visit Trust CenterRequest reports
    SOC 2
    Type II, audited annually
    A+
    VAPT penetration test rating
    US only
    Cloud regions for customer data
    0
    of your data used to train our models

    Written to be checked, not to reassure.

    Primes, agencies and SLED offices set a security bar before a vendor gets near their data. A tool that cannot clear it does not get bought, however good it is.

    The bar rises with the size of the buyer. A small business can adopt software on a card. An enterprise capture team cannot, because the same tool has to survive an IT security review, a legal review of who owns the pipeline data, and a supply-chain review by whichever prime they are teaming with this quarter. Those three reviewers want different documents and none of them wants adjectives.

    So everything below is one of three things: an attestation an independent party issued, a clause you can read for yourself in our Terms of Service or Privacy Policy, or a plain statement that we do not hold something yet. Where the marketing copy and the contract disagreed, we changed the marketing copy.

    Independently verified

    Issued by third parties who tested our systems, not asserted by us. Reports available under NDA from support@samsearch.co.

    • Independent CPA audit · annual

      SOC 2 Type II

      Security, availability and confidentiality controls tested across an audit period rather than checked on a single day. The report enterprise IT and legal ask for by name, available under NDA.

    • Level 1 self-assessed · Level 2 underway

      CMMC Level 2 (in progress)

      Level 1 is held today, self-assessed against the 15 basic requirements in FAR 52.204-21 for safeguarding Federal Contract Information. Level 2, which covers CUI, is in progress and not yet held.

    • Application · API · infrastructure

      VAPT, A+ rating

      Penetration tested by LTS Data Point across the web application, the public APIs and the infrastructure underneath them. Zero critical and zero high-severity findings at certification.

    • ToU 7B · contractual, not configurable

      Your data never trains a model

      Client Data and Output Data are never used to train our models or algorithms. Your library grounds your own drafts and nothing else, and it is never sold.

    • US regions only

      Hosted in the United States

      US cloud regions, with production isolated from staging and development and automated backups. Customer data does not leave them.

    • SAML 2.0 · your identity provider

      Single sign-on

      Accounts provision and deprovision through your own IdP, with role-based permissions, enforced MFA and quarterly reviews of every seat that can reach production.

    Who owns what

    Section 7B of the Terms of Service, in plain language. This is usually the first question your counsel asks and the last one a vendor page answers.

    Data categories and who owns each under the SamSearch Terms of Service
    CategoryOwned byWhat that means
    Client DataYouAnything you input, upload or provide to the Service. You own it. We hold a limited licence to use, process and store it for one purpose: providing and operating the Service.
    Output DataYouReports, insights, predictions and drafts generated from your Client Data. You retain full rights, including to everything the AI writes for you.
    Usage data and metadataSamSearchLogs, performance data and how the Service is used. We own this and use it to operate, secure and improve the platform. It is not your pipeline or your documents.
    Aggregated and anonymised dataSamSearchDerived data that cannot identify you or your organisation, used for analytics and product improvement.
    Model training dataNobodyYour Client Data and Output Data are never used to train our models or algorithms. Not ours, not a shared one, not for machine learning improvement.

    The row worth pausing on is the third. Plenty of vendor pages say “your data is yours” and quietly mean the documents only. Ours says which parts are not: logs, performance data and how the product is used belong to us, and we use them to run and secure the platform. Your pipeline, your documents and everything the AI writes from them are yours.

    How the AI is governed

    The question every enterprise security review now opens with, and the clause that answers it.

    SamSearch is an AI product, so the honest version of this answer matters more than the reassuring one. Terms of Service 7B: we do not use your Client Data or Output Data to train our AI models or algorithms. The Privacy Policy says the same for personal information, content and generated outputs. Neither is a setting someone could switch on for a bigger plan, and retrieval is scoped to your workspace, so when SamSearch drafts against your past performance it is reading your library and nobody else's.

    The second half of AI governance is the part vendors tend to leave out. Section 7 of our Terms requires you to review all generated Content before submission or use, and states plainly that outputs are informational assistance rather than legal, accounting or tax advice. A human signs off before anything reaches a contracting officer. That is not a disclaimer bolted on afterwards; it is how the product is designed to be used, and putting it in the contract is what makes it real.

    No training, contractually

    ToU 7B and the Privacy Policy both prohibit using your data or its outputs to train models. Not configurable, not tier-dependent.

    No pooling across customers

    Retrieval is scoped to your workspace. Your library grounds your drafts and nobody else's.

    Human sign-off required

    ToU 7 requires review before submission. We do not warrant AI output for any particular purpose, and we say so in the contract.

    Platform controls

    The specification behind the summary above. Nothing here is a restatement of it.

    SamSearch platform security controls by area
    AreaControl
    EncryptionAES-256 at rest and TLS 1.2 or higher in transit, with additional encryption layers on sensitive fields.
    HostingUnited States cloud regions. Customer data does not leave them.
    Environment isolationProduction is fully separated from staging and development. Neither carries customer data.
    IdentitySAML 2.0 single sign-on through your own identity provider, so joiners and leavers are handled by your IT team rather than by a support ticket to us.
    AuthorisationRole-based access control, least privilege by default, and MFA enforced across every internal system that can reach production.
    Personnel accessOnly authorised personnel may access customer data, under strict confidentiality obligations. Every seat with production access is reviewed quarterly.
    Vulnerability managementRegular vulnerability scanning and patching, plus dependency scanning on every deploy rather than on a monthly cadence.
    Penetration testingIndependent testing by LTS Data Point across the application, the public APIs and the infrastructure. A+ rated, zero critical or high findings at certification.
    Incident responseA documented and tested plan. Summary shared on request, full plan under NDA.
    Backups and availabilityAutomated backups. ToU 20A sets a 99% monthly uptime target for the core Service; it is a target, and credits exist only where a separate enterprise agreement says so.

    Who else can see it

    Four categories, from the Privacy Policy, and one line about the fifth.

    Categories of third party SamSearch may share information with, and why
    RecipientBasis
    Vendors and service providersCloud hosting and support tooling, bound by our contractual and legal obligations, purely to deliver the Service.
    Integration partnersOnly as part of a workflow you have enabled. Turning an integration off ends the flow of data to it.
    Government or legal authoritiesWhere required by law.
    An acquirer or successorIn the event of a business transfer.
    Nobody, for moneyPersonal information is not sold under any circumstances, and is never shared or distributed to third parties for marketing purposes.

    Our Privacy Policy names categories rather than companies. If your review needs a named subprocessor list, ask support@samsearch.co and we will give you one in writing rather than point you back at this page.

    Frameworks, and where we actually stand

    Including the rows that say no. A reviewer finds those eventually, and it is better they find them here.

    Compliance frameworks and SamSearch's status against each
    FrameworkWhat it coversStatusDetail
    SOC 2 Type IISecurity, availability and confidentiality controls, tested across an audit periodHeldIndependent CPA firm. Report under NDA.
    VAPTPenetration testing of the application, APIs and infrastructureHeld, A+LTS Data Point. Zero critical or high findings at certification.
    FAR 52.204-21The 15 basic safeguarding requirements for Federal Contract InformationAlignedThe control set underneath CMMC Level 1.
    CMMC Level 1Safeguarding Federal Contract Information (FCI)Self-assessedLevel 1 is self-assessment by design under the CMMC rule.
    CMMC Level 2Safeguarding Controlled Unclassified Information (CUI), on NIST SP 800-171Not held, in progressControls are being built to the Level 2 requirements. No assessment date to publish yet.
    FedRAMP HighAuthorisation of a cloud service for use by federal agenciesInherited, not heldThe US cloud infrastructure we run on is FedRAMP High authorized. That authorisation belongs to the provider and covers the infrastructure layer. SamSearch itself is not FedRAMP authorized.

    SamSearch runs on US cloud infrastructure that holds FedRAMP High authorization at the infrastructure layer. That authorization belongs to the provider; SamSearch itself is not FedRAMP or StateRAMP authorized, and does not hold ISO 27001. If your programme requires an authorized system of record, say so early and we will tell you plainly whether we fit.

    For your vendor security review

    What we send, and how fast. Most reviews close on the SOC 2 report alone.

    SOC 2 Type II report

    The full report, including the auditor's opinion and the tested control set. Sent under NDA.

    Penetration test report

    The LTS Data Point VAPT report covering the application, APIs and infrastructure. Sent under NDA.

    CMMC Level 1 self-assessment

    Our scoring against the FAR 52.204-21 safeguarding requirements, and the scope it applies to.

    Architecture and data flow

    Where customer data is stored, what touches it, and which regions it stays in. Written for a reviewer, not a developer.

    Security questionnaire

    We complete your standard questionnaire rather than sending ours back. CAIQ, SIG Lite, or a prime's own form.

    Incident response plan

    Documented and tested. Summary shared on request; the full plan under NDA.

    Send your request to support@samsearch.co and we respond the same business day. If you would rather self-serve, the Trust Center carries our current posture without an NDA in the way. Confidentiality runs both ways before you have signed anything: Terms of Service 7A is a mutual clause covering your client data and business plans as well as our technology and pricing, and it survives termination.

    Security and legal questions we get asked

    In the words they get asked in, answered from the Terms of Service and the Privacy Policy rather than around them.

    Is SamSearch SOC 2 compliant?
    Yes. SamSearch holds SOC 2 Type II, audited annually by an independent CPA firm across the security, availability and confidentiality trust services criteria. Type II means the controls were tested over an audit period rather than checked once on a single day. The full report is available under NDA from support@samsearch.co.
    Do you train AI models on our data?
    No, and it is written into the contract rather than set per account. Section 7B of our Terms of Service states that we do not use your Client Data or Output Data to train our AI models or algorithms, and our Privacy Policy repeats it for personal information, content and generated outputs. Your library grounds your own drafts and nothing else.
    Who owns the data and the AI outputs?
    You own both. Under Terms of Service 7B, Client Data, meaning anything you input or upload, is yours, and we hold only a limited licence to process and store it in order to run the Service. Output Data, meaning the reports, insights and drafts generated from it, is also yours in full. We own usage data and metadata: logs, performance data and how the Service is used.
    Where is our data hosted?
    In United States cloud regions only. Production is isolated from staging and development, and backups are automated. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, with additional encryption on sensitive fields.
    Is SamSearch CMMC certified?
    SamSearch is CMMC Level 1, which covers safeguarding Federal Contract Information and is a self-assessment by design under the CMMC rule. Level 2, which covers Controlled Unclassified Information and maps to NIST SP 800-171, is in progress and is not held today. We would rather you read that here than find it in a questionnaire.
    Are you FedRAMP authorized?
    SamSearch itself is not. We run on US cloud infrastructure that holds FedRAMP High authorization at the infrastructure layer, but that authorization belongs to the provider, and a SaaS product does not inherit its cloud provider's ATO. SamSearch has no FedRAMP package of its own. If your programme requires a FedRAMP-authorized system of record, tell us early and we will say plainly whether we fit.
    What is your uptime SLA?
    Section 20A of our Terms of Service sets a target of 99% uptime for the core Service, measured monthly. Scheduled maintenance, emergency maintenance for security or stability, and causes outside our reasonable control do not count as downtime. That target is not a contractual guarantee and does not by itself create credits or refunds; where an enterprise agreement sets a different commitment, the agreement governs.
    Do you sign an NDA, or is confidentiality already covered?
    It is already covered, in both directions. Terms of Service 7A is a mutual confidentiality clause: your client data, business plans and proprietary materials are Confidential Information, ours are too, each party protects the other's with at least reasonable care, and the obligation survives termination. We will also sign your own NDA when your process requires it.
    Who else can see our data?
    Our Privacy Policy names four categories: vendors and service providers such as cloud hosting and support tooling, bound by contract; integration partners, but only for workflows you have switched on; government or legal authorities where required by law; and an acquirer or successor in a business transfer. Personal information is never sold, under any circumstances, and never shared for marketing purposes.
    Do you support SAML single sign-on?
    Yes. SamSearch supports SAML 2.0 single sign-on through your existing identity provider, so accounts are provisioned and deprovisioned by your IT team rather than by us. Role-based permissions and enforced MFA apply on top of it, and every seat with production access is reviewed quarterly.
    Has SamSearch been penetration tested?
    Yes, by LTS Data Point, across the web application, the public APIs and the cloud infrastructure. The engagement returned an A+ rating with zero critical and zero high-severity findings at the time of certification. The report is available under NDA. We also run dependency scanning on every deploy, patch on a regular cadence, and operate a responsible disclosure route for researchers.
    How long do you keep our data, and can we get it deleted?
    Our Privacy Policy retains personal data only as long as needed to deliver the Service under our contractual obligations, meet legal and regulatory requirements, and enforce our agreements. You can request deletion in accordance with the Terms of Service, along with access to what we hold, correction of anything inaccurate, objection to certain processing, and withdrawal of consent. Requests go to support@samsearch.co. For a retention window committed in writing, ask and we will put it in the agreement.
    Can we rely on AI-generated proposal content without reviewing it?
    No, and our Terms of Service are explicit about it. Section 7 requires users to review all Content before submission or use, and states that we assume no liability for errors or misuse of generated material. Outputs are informational assistance, not legal, accounting or tax advice. SamSearch is built for a human to sign off before anything reaches a contracting officer, and the contract says so.
    Can you complete our vendor security questionnaire?
    Yes. Send us your standard form, whether that is CAIQ, SIG Lite or a prime's own document, and we complete it rather than returning ours. Most reviews also close on the SOC 2 Type II report alone. Requests go to support@samsearch.co and we respond the same business day.
    What happens to our data and our subscription if we cancel?
    Your Client Data and Output Data remain yours and can be exported. Deletion follows the Terms of Service. On the commercial side, terminating yourself does not refund prepaid fees; if we terminate for our own convenience on an annual subscription, section 19 provides a pro-rata refund of the unused portion.
    Who are we actually contracting with?
    Yeul Payments Inc., doing business as SamSearch. That is the entity named in the Privacy Policy and the one your paperwork should reference. Contact for legal, privacy and security requests is support@samsearch.co.
    How will we know if your terms or privacy policy change?
    Where a Privacy Policy change is material we give advance notice by email or on the Site. Terms of Service changes are posted to the site and take effect on continued use, so for anything contractual, an enterprise agreement that fixes the terms for your subscription period is the right instrument. Ask and we will scope one.

    Enterprise-ready. Procurement-approved.

    Request the SOC 2 Type II report, the penetration test, or our CMMC Level 1 self-assessment. Same-day response.

    Visit Trust Center

    SamSearch is operated by Yeul Payments Inc., doing business as SamSearch. Full terms in our Privacy Policy and Terms of Use. Hosted in the United States. Last reviewed: June 2026.

    samsearch

    The Complete AI Platform for Government Contracting

    Platform
    • Product
    • Pricing
    • ROI calculator
    • Integrations
    • Changelog
    Solutions
    • Solutions
    • Customers
    • Comparisons
    • Market watch
    Resources
    • Blog
    • Free GovCon tools
    • Glossary
    • Docs
    Company
    • API & partnerships
    • Careers
    • Support
    • Compliance
    • Trust centre
    • Contact
    Recognised & verified
    SOC 2 Type II Compliant, SamSearchAWS Partner - Advanced, SamSearch on AWS MarketplaceGartner Peer Insights Customer First, SamSearch
    Ask AI about samsearch
    Ask ChatGPTAsk ClaudeAsk Perplexity
    Follow

    © 2026 samsearch. All rights reserved.

    Terms of usePrivacy policy