Skip to content

Security

Your data stays in your cloud.

Sable reads your warehouse to answer a question and reports what it read. It does not copy your rows, it does not keep its own permission list and it never trains on your data.

SOC 2 Type II

GDPR

CCPA

ISO 27001 in progress

HIPAA on request

01

01

Read-only, always

Sable connects with read-only credentials and refuses to start if it is handed anything wider. There is no code path that writes to a customer warehouse, which keeps the review short.

Sable connects with read-only credentials and refuses to start if it is handed anything wider. There is no code path that writes to a customer warehouse, which keeps the review short.

02

02

Permissions come from your warehouse

We do not keep a second copy of who can see what. Every query runs under the asking person’s identity, so row-level policies already in Snowflake, BigQuery or Redshift apply unchanged.

We do not keep a second copy of who can see what. Every query runs under the asking person’s identity, so row-level policies already in Snowflake, BigQuery or Redshift apply unchanged.

03

03

Nothing trains a model

Your schemas, your rows and your questions never enter a training set, ours or a vendor’s. It sits in the contract, not only in the docs.

Your schemas, your rows and your questions never enter a training set, ours or a vendor’s. It sits in the contract, not only in the docs.

04

04

Encryption

TLS 1.3 in transit and AES-256 at rest. Credentials are held in a hardware-backed key store and are never written to logs.

TLS 1.3 in transit and AES-256 at rest. Credentials are held in a hardware-backed key store and are never written to logs.

05

05

Sub-processors

AWS for hosting in us-east-1 and eu-west-1, Stripe for billing and Postmark for email. Changes are announced thirty days in advance.

AWS for hosting in us-east-1 and eu-west-1, Stripe for billing and Postmark for email. Changes are announced thirty days in advance.

06

06

Certifications

SOC 2 Type II, audited every year by an independent US firm. The report and a penetration test summary are available under NDA. ISO 27001 is in progress for 2027.

SOC 2 Type II, audited every year by an independent US firm. The report and a penetration test summary are available under NDA. ISO 27001 is in progress for 2027.

07

07

Incident response

A named engineer is on call around the clock. Customers affected by an incident hear from us within four hours, and a written post-mortem follows within five working days.

A named engineer is on call around the clock. Customers affected by an incident hear from us within four hours, and a written post-mortem follows within five working days.

Ask us anything about this.

Write to security@sable.com and an engineer answers, usually the same day. Questionnaires and the SOC 2 report go out under NDA.

Create a free website with Framer, the website builder loved by startups, designers and agencies.