Skip to main content

Security & Compliance

Security Measures

Samepage implements the following security practices:

  • Secure API-based integrations — All connections to third-party tools use OAuth 2.0 or equivalent secure authentication. Samepage never stores your passwords for connected services.

  • Data isolation per workspace — Each workspace's data is fully isolated from other workspaces.

  • Personal data privacy — Personal integrations (email, calendar, meeting tools) are scoped to the individual user. No one else in the workspace can see personal integration data.

  • No AI model training — Customer data is never used to train AI models. Samepage uses enterprise AI APIs with contractual data protection commitments.

  • Encrypted connections — All data in transit is encrypted via TLS/HTTPS.

Compliance

GDPR

Samepage is GDPR compliant. It processes personal data on behalf of customers with clear purpose, strong access controls, and full transparency about data usage.
​

CCPA

Samepage is CCPA compliant. It acts as a service provider and never sells customer data.
​

SOC 2

SOC 2 certification is planned. Third-party security testing is also planned.
​

Data Retention

  • Imported data is retained as long as the integration is active and the workspace is in use

  • Generated outputs (Signal results) are retained for reference

  • Configuration data (Signals, filters, instructions) is retained as long as the workspace is active

Permissions and Access

When connecting integrations, Samepage requests only the permissions needed to import relevant data:

  • Read-only access for most integrations — Samepage reads data from your tools but does not modify it

  • Scoped permissions — Samepage requests the minimum necessary API scopes for each integration

  • Users can disconnect integrations at any time, which stops data import from that source

Reporting Security Concerns

If you identify a security concern or vulnerability, contact the Samepage team directly.
​

Did this answer your question?