Security Measures
Samepage implements the following security practices:
Secure API-based integrations — All connections to third-party tools use OAuth 2.0 or equivalent secure authentication. Samepage never stores your passwords for connected services.
Data isolation per workspace — Each workspace's data is fully isolated from other workspaces.
Personal data privacy — Personal integrations (email, calendar, meeting tools) are scoped to the individual user. No one else in the workspace can see personal integration data.
No AI model training — Customer data is never used to train AI models. Samepage uses enterprise AI APIs with contractual data protection commitments.
Encrypted connections — All data in transit is encrypted via TLS/HTTPS.
Compliance
GDPR
Samepage is GDPR compliant. It processes personal data on behalf of customers with clear purpose, strong access controls, and full transparency about data usage.
CCPA
Samepage is CCPA compliant. It acts as a service provider and never sells customer data.
SOC 2
SOC 2 certification is planned. Third-party security testing is also planned.
Data Retention
Imported data is retained as long as the integration is active and the workspace is in use
Generated outputs (Signal results) are retained for reference
Configuration data (Signals, filters, instructions) is retained as long as the workspace is active
Permissions and Access
When connecting integrations, Samepage requests only the permissions needed to import relevant data:
Read-only access for most integrations — Samepage reads data from your tools but does not modify it
Scoped permissions — Samepage requests the minimum necessary API scopes for each integration
Users can disconnect integrations at any time, which stops data import from that source
Reporting Security Concerns
If you identify a security concern or vulnerability, contact the Samepage team directly.
