Trust

Trust and security

Salera works with some of the most sensitive information a company holds, and treats its protection as the first priority. Every review is designed so that the client stays in control of its data, from the first connection to the final deletion.

Read-only access
Read-only permissions approved by the client's IT contact
Isolated per client
One private cloud machine per client
Never used for training
Zero-data-retention agreements with Anthropic and OpenAI
Deleted after the engagement
Formal retention and disposal procedures
Trust Center

See every security control in the Salera Trust Center, or email [email protected] for a security review.

QR code for the Salera Trust Center
Security concept

The commitments behind every review

Each commitment describes how Salera works, and the client agreement sets the exact terms of each engagement.

01

You decide what Salera reads

Salera reads only the sources the client approves. The client can limit any source to a channel, folder, or field, leave out any mailbox, team, or system, and turn on automatic filters that remove sensitive files and email.

Scope agreed with management before any agreement is signed

02

Nothing is ever written back

Every connection is read-only. Salera does not write to, change, or send from client systems, and setup needs no network or firewall changes.

Read-only permissions approved by the client's IT contact

03

Each client's data stays separate

Each client gets its own private cloud machine behind a firewall, and no two clients share an environment. Clients with stricter rules can run Salera in their own cloud or on their own servers.

One private cloud machine per client

04

Never used to train AI models

Model providers process data under zero-data-retention agreements and never keep it. Client data is never used to train any model. Clients can also run local models on their own infrastructure.

Zero-data-retention agreements with Anthropic and OpenAI

05

Kept only as long as the engagement

Data stays only for the length of the engagement and is securely deleted when it ends, or at any point on request. A cold-storage backup is kept only if the client asks for one.

Formal retention and disposal procedures

06

Findings about systems, not people

Salera studies how work moves between teams. Findings describe processes, roles, boundaries, incentives, and systems, never the performance of named individuals. Staff review only a minimal amount of underlying data directly.

Final results checked by hand for quality

Data lifecycle

What happens to client data, from agreement to deletion

Client data enters a dedicated, read-only environment, stays there while Salera works, and is deleted when the engagement ends.

01

Agree

Management and Salera agree the scope. Salera signs the client's NDA and a data processing agreement before any data is shared.

Isolated client environment · read-only
02

Connect

The client's IT contact approves each read-only connection. Sign-in runs through Microsoft Entra ID.

03

Analyze

Analysis runs on the client's dedicated machine. Data is encrypted in transit, and model providers keep nothing.

04

Deliver

Staff check the final results for quality. Each finding links to the record behind it.

05

Delete

Data is securely deleted at the end of the engagement, or earlier on request.

Security controls

How the environment is protected

Salera runs its security program on a defined set of controls, grouped below by area. Each one is listed in the Salera Trust Center.

Infrastructure

  • Network firewalls configured against unauthorized access
  • Intrusion detection with continuous monitoring
  • Central log management
  • Infrastructure monitoring with threshold alerts
  • Hardening standards reviewed at least once a year

Access

  • Privileged access to keys, production systems, databases, and firewalls limited to staff with a business need
  • Unique credentials or keys for every system, application, and production sign-in
  • Sign-in through Microsoft Entra ID
  • Passwords configured according to a written policy

Data

  • Data encrypted in transit over public networks
  • Data classification policy
  • Formal retention and disposal procedures
  • Certificate of destruction for every device destroyed

Secure development

  • Changes reviewed, tested, and approved before production
  • Only authorized staff can deploy to production
  • Formal development life cycle
  • Documented vulnerability management and system monitoring

Resilience and response

  • Documented security and privacy incident response
  • Incidents logged, tracked, resolved, and communicated to affected parties
  • Business continuity and disaster recovery plans
  • Control self-assessments at least once a year

Governance and risk

  • Risk assessments at least once a year, including fraud risk
  • Documented risk management program with mitigation plans
  • Security policies reviewed at least once a year
  • Security roles and responsibilities formally assigned
  • Vendor management with an annual review of critical vendors
Compliance and assurance

Where Salera stands today

Salera reports certification work as in progress until each audit is complete.

In place today
NDA and data processing agreement
Signed with every client before any data is shared.
Model provider agreements
Zero-data-retention terms with model providers, including Anthropic and OpenAI.
Insurance
Coverage for damages from data leakage, available where applicable.
In progress
SOC 2 Type II
An independent auditor's report on how security controls operate over time.
ISO 27001
The international standard for managing information security.
GDPR
The EU's data protection rules. Data processing agreements are available during onboarding.
Questions

Common questions from security teams

Review levels, setup steps, and hosting options are described on How it works.

01

Who at Salera can see client data?

+

Analysis runs on the client's dedicated machine. Salera staff review the final results by hand for quality, and only a minimal amount of underlying data is reviewed directly. Privileged access is limited to authorized staff with a business need.

02

Can Salera run in our own cloud or on our servers?

+

Yes. The standard setup is a private Salera cloud machine for each client, which is the fastest start. Salera can also run inside the client's own cloud account or on its own servers, with more setup work.

03

What happens if there is a security incident?

+

Salera has documented security and privacy incident response policies. Incidents are logged, tracked, resolved, and communicated to affected parties according to those policies.

04

How much work is setup for our IT team?

+

Setup needs at least one IT contact and a call with Salera, and usually one to four hours of client IT time, depending on how many sources are connected. No network or firewall changes are needed.

05

How do we start a security review?

+

Email [email protected]. The full list of controls is published in the Salera Trust Center, and the client agreement sets the exact scope and terms of each engagement.

Last updated October 2026 · Security contact: [email protected] · To report a security concern, email the same address.

Operating analysis on demand

Put company-wide analysis behind your next decision.

Salera reads approved company data through read-only access and ranks what it finds by value.