SSO and provisioning
Configure SAML 2.0 or OpenID Connect for sign-in and SCIM 2.0 for provisioning. Configuration is off by default and should be tested with your identity provider before an administrator enables it.
Identity, audit, retention, and report branding sit on top of the same interview and analysis product. We confirm security facts in writing and do not use certification language without current evidence.
Access is granted to the organization and enforced on the server. A client-side setting alone cannot unlock these controls.
Configure SAML 2.0 or OpenID Connect for sign-in and SCIM 2.0 for provisioning. Configuration is off by default and should be tested with your identity provider before an administrator enables it.
Organization admins can filter and page through recorded events, then export the same filtered history as CSV.
Set a workspace retention window with an explicit confirmation. Dry-run status is visible before an enforcement job changes data.
Add an organization logo and accent color to public reports and threads. Attribution can be hidden only when the server confirms Enterprise.
Custom volume, invoicing, implementation, and procurement terms are handled through a written order rather than a hidden checkout price.
We review healthcare requirements with your team. This page does not claim HIPAA eligibility or promise a BAA.
We do not state a SOC 2 certification on this page. Ask the security team for the current status, scope, and evidence before relying on it in a vendor review.
Our Privacy Policy describes data use, rights, and deletion requests. Send your DPA requirements for contract review; this page is not a substitute for the signed terms.
We do not use Customer Data to train models that we develop. Research content is processed by contracted AI providers when a requested feature requires it. Provider and retention details are confirmed in the security review for your deployment.
Hosting region and any residency commitment are confirmed in writing during procurement. We make no EU-residency promise on this page without a deployment-specific commitment.
Request the current subprocessor list from security. A dated list supplied during review is more reliable than an unversioned claim here.
Share your questionnaire and required evidence list. We will tell you which documents exist, their dates, and which requests need contract language before signature.
Include your identity provider, retention window, hosting needs, and evidence requirements so the first response is useful.