SAM·AI · Trust

Security & Trust

Last updated: June 3, 2026

Security is foundational to federal-capture work — you are trusting SAM·AI with sensitive opportunity data, draft proposals, and the documents that shape your pipeline. This page explains exactly how we protect that data, what access SAM·AI does and does not have, and how you stay in control.

Encryption

Encrypted in transit and at rest

All traffic to and from SAM·AI is protected with TLS 1.2 or higher. Stored data is encrypted at rest, and application secrets are held in isolated, per-service stores — never embedded in code, logs, or URLs.

Scoped Google Drive Access

Least-privilege access to only what it creates

SAM·AI connects to Google Drive through OAuth using the least-privilege drive.file scope. That means SAM·AI can only see the files it creates on your behalf — not your whole Drive. Your documents stay in your Drive: SAM·AI streams what it needs on demand and discards it, storing only references and an index — never a parallel copy of your data.

No Model Training

Your data is never used to train AI models

Your documents, opportunity records, and capture data are never used to train AI models — ours or any third party's. Your information works for your pursuits and nothing else.

Zero Trust

Assume-breach architecture

SAM·AI is built on Zero Trust principles: default-deny access, network segmentation, scoped and ephemeral identity, least privilege throughout, and assume-breach containment that limits the blast radius of any single failure.

Access Controls

Access to your data is governed and audited end to end.

Infrastructure

SAM·AI runs behind a hardened edge and segmented services.

Data Residency & Ownership

You own your data, and it lives where you keep it. Your documents remain in your Google Drive — SAM·AI does not hold a separate master copy. Because access is granted through OAuth, you can revoke SAM·AI's access at any time directly from your Google account, and that access ends immediately.

Monitoring & Incident Response

We monitor continuously and respond deliberately. The platform runs self-healing watchdogs that detect and recover from service disruptions, backed by a defined incident-response process for triage, containment, and communication. Current platform health is published on our status page.

Compliance Posture

As the program matures, we align our controls with widely recognized security and privacy frameworks — including SOC 2 trust-service principles, NIST guidance, and privacy regimes such as GDPR and CCPA. We are working toward and designing against these standards; we describe them honestly as alignment goals and do not claim certifications we do not yet hold.

Responsible Disclosure

If you believe you have found a security vulnerability, we want to hear from you. Report it to [email protected] and we will investigate promptly. We appreciate the security community's help in keeping SAM·AI and our customers safe.

Contact

Questions about our security practices, data handling, or compliance posture? Reach our team at [email protected].

Talk to us about security