Governance
Policies, principles, and accountability
SinglepointAI’s security program establishes policies and controls for how we protect customer data and systems, monitors adherence to those controls, and continuously improves them. Security & Compliance is a first-class category in the platform architecture alongside document ingestion, understanding, and field mapping.
- 01Least privilege
Access is limited to people with a legitimate business need and granted based on the principle of least privilege.
- 02Defense in depth
Controls are layered across identity, network, application, and data so no single failure exposes customer information.
- 03Consistent application
Security controls are applied consistently across production systems, corporate environments, and vendor relationships.
- 04Continuous improvement
Controls mature over time toward better effectiveness, clearer auditability, and lower operational friction.
Data protection
Encryption in transit and at rest
Data at rest
Customer data stored in Azure-backed datastores is encrypted at rest using platform-managed encryption. Sensitive configuration and secrets are segregated from application data and protected with restricted access.
Data in transit
Data transmitted over public networks uses TLS 1.2 or higher. Production endpoints enforce encrypted connections to protect traffic between clients, APIs, and integrated partner systems.
Secret management
Application secrets, API credentials, and encryption keys are stored in Azure secret management services. Access is limited to authorized services and personnel under least-privilege policies.
Tenant isolation
Strict tenant-level data isolation keeps each firm’s plan data scoped to its own environment. AskSPIA runs in an isolated Azure environment with no open-internet access and answers only retirement-plan-related interactions.
Infrastructure security
Azure-native hosting for regulated workflows
SPAI runs on Microsoft Azure. Production infrastructure is designed for regulated retirement workflows with network segmentation, monitoring, and environment separation between development, staging, and production.
- Azure-native hosting with hardened cloud configuration baselines
- Environment separation so production data is not used in lower environments unless explicitly controlled
- Logging and monitoring of security-relevant events across critical services
- Vendor and subprocessors evaluated for access to customer or production data
Access control
Identity, roles, and human oversight
Access to SinglepointAI systems requires authenticated identity. Employee access is granted by role, reviewed periodically, and revoked when employment or business need ends.
- Role-based access for internal systems and production tooling
- Multi-factor authentication for privileged and remote access paths
- Maker/checker workflows, exception review, and approval steps inside the product so final oversight stays with qualified customer staff
- Immutable audit trails for material automation and approval events
Secure development
How we build and ship the platform
Security is part of the software development lifecycle, from design through deployment.
- Code review and controlled change management before production releases
- Dependency and vulnerability awareness as part of ongoing engineering practice
- Separation of duties between development and production access where practical
- Human-in-the-loop product design so automation does not become unsupervised decision-making
Incident response
Detect, contain, and communicate
SinglepointAI maintains an incident response process covering detection, triage, containment, eradication, recovery, and post-incident review. Security events are assessed for customer impact, and affected customers are notified in accordance with contractual and legal obligations.
If you believe you have identified a security issue affecting SinglepointAI systems, contact security@singlepointai.com.
Compliance
Frameworks and customer assurance
SinglepointAI maintains a formal security and compliance program and continuously evaluates relevant frameworks for retirement technology and SaaS operations. We work with customers and their auditors to support security reviews, questionnaires, and due diligence.
- Security policies covering access control, data protection, vendor risk, and incident response
- Evidence collection and control monitoring to support customer assurance requests
- Alignment with privacy commitments described in our Privacy Policy
For SOC reports, questionnaires, or a deeper security review under NDA, email sales@singlepointai.com.
Contact
Questions about security
Security and procurement questions: sales@singlepointai.com
Suspected security issues: security@singlepointai.com
Related documents: Privacy Policy · Terms of Service
Last updated