Security & privacy

Designed for FERPA-aware data handling.

Sam is in active development. The page below is a working summary of how we handle data today — not a marketing sheet, not a certification claim. If you're reviewing Sam for IT, email sami@trysam.co and we'll send the current write-up with full details.

PII redaction

Inbound messages are scanned for personally identifying information before they hit logs. Names, phone numbers, and emails are redacted in transcripts available to admins by default; full transcripts are accessible to authorized roles only.

Configurable retention

Default retention is 90 days. Configurable up or down per school's policy. Deletion is real deletion — not tombstoned rows.

Admin audit log

Every admin action — source uploads, source retirement, CSV exports, transcript views — is recorded with user, timestamp, and target.

No training on your data

Your school's content is used to retrieve answers for your school. It is never used to train shared models or made available to other tenants.

Per-tenant data isolation

Each school's sources, embeddings, and transcripts live in a logically isolated index. Cross-tenant queries are not possible by design.

US-based hosting

Application and data hosted in US regions. Subprocessors are listed on request as part of IT review.

What this page is not. Sam does not currently advertise SOC 2 or other formal certifications. We're happy to walk through our current controls in detail and to scope additional requirements with your school. Final compliance review with your school is part of every onboarding.