Written for review, not for marketing

Security & deployment

This page covers Savanto Desk, the hosted platform. Engagement work that runs on your own infrastructure is governed by your architecture and your controls, not by this page. If your team needs something not covered here, ask. We’d rather answer it now than at contract stage. For contractual terms, see the Data Processing Agreement (available on request) and our Privacy Policy.

LAST REVIEWED · AUGUST 2026


Deployment

Desk currently runs as a managed deployment: we host it, and your content and configuration live in your own isolated tenant. Where an engagement calls for a different topology (your cloud account, or a restricted environment), that work is scoped and proven as part of the engagement itself, and we will tell you plainly what has been run before and what would be new. Where an engagement builds software that runs entirely in your environment, we host nothing and the controls below do not apply.

Managed (Savanto cloud)
We host and operate Desk on AWS in the United States, under the controls described on this page. Your content sits in your own isolated tenant; you keep ownership, and can export or delete it at any time.
YOUR ENVIRONMENTYour contentWEBSITE · CMS · CATALOGYour people & applicationsWIDGET · API · MCP AGENTSYour systems of recordORDERS · POLICIES · ERPSAVANTO CLOUD · AWS · USYOUR ISOLATED TENANTContent indexEXPORT OR DELETE ANY TIMEAnswer engineRETRIEVE · COMPOSE · ANSWERMODEL PROVIDERYour vendor listOPENAI · ANTHROPICAZURE OPENAI · BEDROCKSELF-HOSTEDCRAWL · READ-ONLYOR API PUSHTLSIN TRANSITAUTHENTICATEDYOUR GRANTREVOCABLEPROMPT +CONTEXTNO TRAININGDPA
The managed deployment as it runs today. Access to your systems of record is granted by you, scoped to your tenant, and revocable at any time. Conversation transcripts delete after 90 days; indexed content is yours to export or delete.

Model providers

Your approved-vendor list decides which models Desk uses. Where a provider is already on your list, we use it rather than asking you to add one.

Provider options
OpenAI, Anthropic, Azure OpenAI, AWS Bedrock, or self-hosted open-weight models. If your approved list names a different provider, ask; most are a small lift.
No training on your data
Your content and conversations are never used to train models. This is contractual, not a setting; it appears in the DPA.

Data handling

What we process
The content you index for search and chat, plus visitor interactions with the widgets: chat messages, search queries, IP addresses, browser/session identifiers, and any contact details a visitor voluntarily submits. Customers are contractually prohibited from submitting special-category (sensitive) personal data.
Personal-data safeguard
The assistant is designed not to collect personal data and never asks for it. An automatic safeguard detects common personal-data patterns (card numbers, government identifiers, phone numbers, addresses) and stops the message before the assistant processes it.
Retention
Conversation transcripts are retained for 90 days by default, then deleted. Indexed content is retained until you remove it. Custom retention periods can be agreed in your order form.
Data ownership
You own your data. Full export at any time.

Platform security

Encryption in transit
TLS 1.2 or higher. All internal service-to-service traffic is encrypted.
Encryption at rest
AES-256 via AWS managed services.
Tenant isolation
Logical segregation by tenant across all data stores.
Infrastructure
Production workloads run on AWS managed services; service-to-service access is authenticated and authorized through AWS IAM. Public endpoints sit behind AWS-managed edge protections, including TLS termination and DDoS mitigation.
Access control
Production access requires multi-factor authentication, is granted least-privilege, reviewed periodically, and logged.
Vulnerability management
Dependency and secret scanning run on every change, pre-commit and in continuous integration.
Monitoring
Anomalous activity alerts an on-call rotation. Production deployments are traceable.
Incident response
A documented process covers detection, containment, investigation, customer notification, and post-incident review. Personal-data breaches are notified without undue delay, and no later than 72 hours after we become aware.
Personnel
All personnel with access to customer data are bound by confidentiality obligations and receive security-awareness guidance at onboarding.

Subprocessors & compliance

Subprocessors
Amazon Web Services, Inc. · OpenAI, LLC · Anthropic, PBC. Current list on request.
SOC 2 Type II
In progress. Target Q2 2027. Available for discussion under NDA in the meantime.
Data Processing Agreement
Available on request; executed before any production data is processed.
Breach notification
Contractual notification commitments are set out in the DPA.

Integration reference

The platform documentation is public. If your team wants to judge the integration surface before a call, these are the pages they will want.

Authentication & API
Scoped keys, OAuth 2.1, and the REST surface: authentication, rate limits.
Your systems, as tools
Custom domains backed by your own MCP servers, so answers can require a live lookup: domains & tools, MCP server.
Events & streaming
Webhooks for downstream systems, and streaming for embedded surfaces.

Send the questionnaire.

We’d rather work through it early than discover a blocker at contract stage, and we’ll tell you plainly where the answer is “not yet” rather than “yes, with caveats.”

sean@savanto.ai