Skip to main content

Security & Compliance

Security Measures

Samepage implements the following security practices:

  • Secure API-based integrations — All connections to third-party tools use OAuth 2.0 or equivalent secure authentication. Samepage never stores your passwords for connected services.

  • Data isolation per workspace — Each workspace's data is fully isolated from other workspaces.

  • Personal data privacy — Personal integrations (email, calendar, meeting tools) are scoped to the individual user. No one else in the workspace can see personal integration data.

  • No AI model training — Customer data is never used to train AI models. Samepage uses enterprise AI APIs with contractual data protection commitments.

  • Encrypted connections — All data in transit is encrypted via TLS/HTTPS.

Compliance

GDPR

Samepage is GDPR compliant. It processes personal data on behalf of customers with clear purpose, strong access controls, and full transparency about data usage.

CCPA

Samepage is CCPA compliant. It acts as a service provider and never sells customer data.

SOC 2

SOC 2 certification is planned. Third-party security testing is also planned.

Data Retention

  • Imported data is retained as long as the integration is active and the workspace is in use

  • Generated outputs (Signal results) are retained for reference

  • Configuration data (Signals, filters, instructions) is retained as long as the workspace is active

Permissions and Access

When connecting integrations, Samepage requests only the permissions needed to import relevant data:

  • Read-only access for most integrations — Samepage reads data from your tools but does not modify it

  • Scoped permissions — Samepage requests the minimum necessary API scopes for each integration

  • Users can disconnect integrations at any time, which stops data import from that source

Reporting Security Concerns

If you identify a security concern or vulnerability, contact the Samepage team directly.

Did this answer your question?