Trust and security
Salera works with some of the most sensitive information a company holds, and treats its protection as the first priority. Every review is designed so that the client stays in control of its data, from the first connection to the final deletion.
- Read-only access
- Read-only permissions approved by the client's IT contact
- Isolated per client
- One private cloud machine per client
- Never used for training
- Zero-data-retention agreements with Anthropic and OpenAI
- Deleted after the engagement
- Formal retention and disposal procedures
See every security control in the Salera Trust Center, or email [email protected] for a security review.
The commitments behind every review
Each commitment describes how Salera works, and the client agreement sets the exact terms of each engagement.
You decide what Salera reads
Salera reads only the sources the client approves. The client can limit any source to a channel, folder, or field, leave out any mailbox, team, or system, and turn on automatic filters that remove sensitive files and email.
Scope agreed with management before any agreement is signed
Nothing is ever written back
Every connection is read-only. Salera does not write to, change, or send from client systems, and setup needs no network or firewall changes.
Read-only permissions approved by the client's IT contact
Each client's data stays separate
Each client gets its own private cloud machine behind a firewall, and no two clients share an environment. Clients with stricter rules can run Salera in their own cloud or on their own servers.
One private cloud machine per client
Never used to train AI models
Model providers process data under zero-data-retention agreements and never keep it. Client data is never used to train any model. Clients can also run local models on their own infrastructure.
Zero-data-retention agreements with Anthropic and OpenAI
Kept only as long as the engagement
Data stays only for the length of the engagement and is securely deleted when it ends, or at any point on request. A cold-storage backup is kept only if the client asks for one.
Formal retention and disposal procedures
Findings about systems, not people
Salera studies how work moves between teams. Findings describe processes, roles, boundaries, incentives, and systems, never the performance of named individuals. Staff review only a minimal amount of underlying data directly.
Final results checked by hand for quality
What happens to client data, from agreement to deletion
Client data enters a dedicated, read-only environment, stays there while Salera works, and is deleted when the engagement ends.
Agree
Management and Salera agree the scope. Salera signs the client's NDA and a data processing agreement before any data is shared.
Connect
The client's IT contact approves each read-only connection. Sign-in runs through Microsoft Entra ID.
Analyze
Analysis runs on the client's dedicated machine. Data is encrypted in transit, and model providers keep nothing.
Deliver
Staff check the final results for quality. Each finding links to the record behind it.
Delete
Data is securely deleted at the end of the engagement, or earlier on request.
How the environment is protected
Salera runs its security program on a defined set of controls, grouped below by area. Each one is listed in the Salera Trust Center.
Infrastructure
- Network firewalls configured against unauthorized access
- Intrusion detection with continuous monitoring
- Central log management
- Infrastructure monitoring with threshold alerts
- Hardening standards reviewed at least once a year
Access
- Privileged access to keys, production systems, databases, and firewalls limited to staff with a business need
- Unique credentials or keys for every system, application, and production sign-in
- Sign-in through Microsoft Entra ID
- Passwords configured according to a written policy
Data
- Data encrypted in transit over public networks
- Data classification policy
- Formal retention and disposal procedures
- Certificate of destruction for every device destroyed
Secure development
- Changes reviewed, tested, and approved before production
- Only authorized staff can deploy to production
- Formal development life cycle
- Documented vulnerability management and system monitoring
Resilience and response
- Documented security and privacy incident response
- Incidents logged, tracked, resolved, and communicated to affected parties
- Business continuity and disaster recovery plans
- Control self-assessments at least once a year
Governance and risk
- Risk assessments at least once a year, including fraud risk
- Documented risk management program with mitigation plans
- Security policies reviewed at least once a year
- Security roles and responsibilities formally assigned
- Vendor management with an annual review of critical vendors
Where Salera stands today
Salera reports certification work as in progress until each audit is complete.
- NDA and data processing agreement
- Signed with every client before any data is shared.
- Model provider agreements
- Zero-data-retention terms with model providers, including Anthropic and OpenAI.
- Insurance
- Coverage for damages from data leakage, available where applicable.
- SOC 2 Type II
- An independent auditor's report on how security controls operate over time.
- ISO 27001
- The international standard for managing information security.
- GDPR
- The EU's data protection rules. Data processing agreements are available during onboarding.
Common questions from security teams
Review levels, setup steps, and hosting options are described on How it works.
01Who at Salera can see client data?
+
Analysis runs on the client's dedicated machine. Salera staff review the final results by hand for quality, and only a minimal amount of underlying data is reviewed directly. Privileged access is limited to authorized staff with a business need.
02Can Salera run in our own cloud or on our servers?
+
Yes. The standard setup is a private Salera cloud machine for each client, which is the fastest start. Salera can also run inside the client's own cloud account or on its own servers, with more setup work.
03What happens if there is a security incident?
+
Salera has documented security and privacy incident response policies. Incidents are logged, tracked, resolved, and communicated to affected parties according to those policies.
04How much work is setup for our IT team?
+
Setup needs at least one IT contact and a call with Salera, and usually one to four hours of client IT time, depending on how many sources are connected. No network or firewall changes are needed.
05How do we start a security review?
+
Email [email protected]. The full list of controls is published in the Salera Trust Center, and the client agreement sets the exact scope and terms of each engagement.
Last updated October 2026 · Security contact: [email protected] · To report a security concern, email the same address.
Put company-wide analysis behind your next decision.
Salera reads approved company data through read-only access and ranks what it finds by value.


