Trust Center

How is my data encrypted?

In transit, TLS 1.2 or higher; the application refuses unencrypted HTTP and asserts HTTP Strict Transport Security. At rest, AES-256 including backups, with provider-managed keys. Customer-managed keys (CMK/BYOK) are not offered. (Security Addendum § 4)

Is my data pooled with other customers'?

No. Each customer has a dedicated database and object store. Platform systems hold identity and billing information only, never case content. The tenant database, object store, and processing tier have no public endpoint. (§ 3.1–3.2)

Do the AI models train on my data?

No. Neither SNT Counsel nor any model provider trains, fine-tunes, or otherwise improves a model on your data, inputs, or outputs. Providers are engaged on commercial or enterprise terms that prohibit it, and zero data retention is configured on provider paths where it is offered and technically available. (§ 6.1)

What is retained, and for how long?

Your documents and work product stay in your tenant for the life of the subscription and are exportable at any time. Model providers retain nothing on paths configured for zero data retention; real-time voice sessions are the disclosed exception and can be disabled by a tenant administrator. Audit records are retained for seven years and cannot be deleted, including by an SNT Counsel administrator. (§ 6.7, § 7.2–7.3, § 15)

Who at SNT Counsel can access my data?

No one by default. Production access is limited to the fewest named individuals required to operate the Service, is available only over an authenticated VPN, is read-only unless the task requires more, and is logged. Personnel are background-screened where lawful and bound by written confidentiality obligations. (§ 5.3, § 2.4)

Where is my data stored?

In Microsoft Azure regions located in the United States, consistent with Section 11 of the DPA. A dedicated-plan deployment with private interconnect is available for firms that require it. (§ 3.6, § 14.1(d))

Do you run penetration tests?

An independent third-party penetration test of the production application is performed at least once every twelve months, with the first engagement within twelve months of August 31, 2026. A summary of findings and remediation status is available to customers on request. Vulnerabilities are remediated by severity: critical within 7 days, high 30, medium 90, low 180. (§ 9.4–9.5)

How quickly would you tell us about a security incident?

Without undue delay and in any event within 48 hours of confirming that an incident affected your data, to the security or administrative contact on your account, with a second channel if the first is unavailable. Confirmed customer-impacting availability incidents are posted to status.sntlabs.io within 15 minutes. (§ 10.2, § 10.7)

What happens to my data when we leave?

Your data, content, and audit records are available for export for 30 days after the subscription ends. After that, or earlier on written request, data is returned or deleted under Section 13 of the DPA, and a written certification of deletion is available on request. (§ 15)