San Francisco
Trust

Security for the action path.

Salus sits in front of consequential execution. Security, isolation, and clear decision records are part of that boundary from the start.

Core controls

How Salus protects your data.

The authorization path is designed to receive only what a decision needs, keep workspaces separated, and leave an inspectable record.

01 · Encrypted

Data is encrypted in transit and at rest.

External connections use HTTPS. Stored production data is encrypted at rest, with selected credentials protected again at the application layer.

02 · Isolated

Workspaces are isolated.

Workspace-scoped access controls and database policies separate tenant data. Requests fail closed when the required scope is absent.

03 · Minimized

Send only what the decision needs.

The standard path uses the proposed tool call and the context chosen for its decision. Raw audio, full transcripts, card data, and unrelated PII are not required.

04 · Controlled

Control retention, export, and deletion.

Retention and redaction are configurable. Decision records can be exported, and workspace or account data can be deleted.

Assurance

Compliance and regulated workloads.

We keep the public claims narrow and share the detail your security process needs directly.

ComplianceSOC 2 Type II in progress.

Ask us for current scope, controls, and supporting documentation.

Regulated workloadsBAAs for workloads involving PHI.

We review the deployment and data path before regulated production use.

Security review

We’ll support your security review.

We share the security, privacy, data-handling, and subprocessor information your review requires. Report an issue or request documentation directly from the team.