Skip to contentSofie Regulatory Intelligence: nine regulators, one place, updated every day.

Security

Your environment.Your data.Your decisions.

Every customer runs Sofie in its own isolated AWS environment, with enterprise sign-in, human approval for consequential actions and a record your quality and security teams can review.

Eight commitments, in every deployment.

These apply to every customer deployment.

  • An isolated deployment for every customer

    Your own AWS environment: a dedicated VPC, private subnets and an encrypted database. Never shared.

  • Your data never trains a model

    Customer content is used to do your work, and nothing else.

  • Enterprise sign-in

    SAML SSO with Okta, Entra ID, Google and more, passkey MFA and configurable idle timeouts.

  • Human approval where it matters

    Sending, sharing and unattended work pause for approval by default.

  • Evidence for every conclusion

    Answers carry page-level citations; missing evidence is flagged, never invented.

  • Audit trail and access reviews

    Security events, access reviews and record history you can hand to an auditor.

  • Governed memory

    Admins decide what Sofie learns and retains, by user, team or site.

  • SOC 2 program underway

    Controls mapped and monitored continuously ahead of our SOC 2 audit.

Isolated deployment

One customer, one environment.

Sofie is deployed privately for each customer. Your application, automation and database live in your own network on AWS, never alongside another customer’s.

  • Dedicated VPC

    A separate virtual network per customer, with VPC flow logs.

  • Private subnets

    Application and database tiers run in private subnets within that network.

  • Encrypted Aurora

    Your data is stored in an encrypted Aurora PostgreSQL database of your own.

  • AWS Bedrock

    Knowledge bases, embeddings and memory run on AWS Bedrock.

Your people

  • SSO sign-in
  • Passkey MFA and step-up

Your dedicated AWS environment

Single tenant

Dedicated VPC · flow logs enabled

Private application subnets

Sofie applicationOrchestrations and Sequences

Private database subnets

Aurora PostgreSQLEncrypted at rest

AWS Bedrock

  • Knowledge bases
  • Embeddings and memory

Another customer’s environment: its own VPC, subnets and database

No shared tenancy

People sign in with single sign-on and passkey MFA to a dedicated AWS environment for each customer. Inside a dedicated VPC with flow logs, the Sofie application and automation run in private application subnets and data is stored in an encrypted Aurora PostgreSQL database in private database subnets. Knowledge bases, embeddings and memory use AWS Bedrock. Other customers run in entirely separate environments.

Identity & access

The right people, and only them.

Sign-in, session and permission controls your IT team already expects, applied to every workspace, document and Surface.

  • Single sign-on

    SAML SSO with Okta, OneLogin, JumpCloud and Auth0, plus Okta, Microsoft Entra ID and Google sign-in. Email magic links where SSO is not in place.

  • Passkey MFA with step-up

    Passkeys as a second factor, with a fresh check before sensitive actions.

  • Idle timeout you set

    Sessions end after a period of inactivity you choose, from 15 minutes to 24 hours (1,440 minutes).

  • Roles built from fine-grained permissions

    Workspace owner, admin, editor and viewer roles built from 19 permissions, and organization-wide workspace roles for broader programs.

  • Guest access by invitation

    External partners see only what their invitation allows, with Owner, Editor, Viewer or Responder access. Invitations last 14 days by default, up to a year.

  • Protected connections

    OAuth tokens for connected systems are encrypted, and service-to-service calls are signed.

AI governance

Sofie drafts. People decide.

Anything consequential waits for a person. Everything Sofie concludes carries its evidence.

Sequence · Weekly supplier digest

Waiting for approval

Sofie wants to

Send an email to 4 recipients

To supplier-quality@larkspurbio.com +3

Subject Approved suppliers: one new Form 483 posted

3 sources cited · draft attached

Approve and sendEdit draftDecline
  1. 01

    Human approval by default

    Sending email, writing to calendars, updating Salesforce or Monday.com and posting to team messaging pause for a person to approve, including in unattended Sequences.

  2. 02

    Pre-approvals that expire

    Teams can pre-approve routine actions for a period. Pre-approvals are optional and expire.

  3. 03

    Citations on every conclusion

    Answers and drafts carry page-level citations. When the evidence is missing, Sofie names the gap instead of filling it from memory.

  4. 04

    Governed memory

    Administrators turn memory on or off by user, team or site. It never crosses organization boundaries and respects your retention window.

  5. 05

    Server-checked actions

    Actions on Surfaces run through server-enforced eligibility rules, duplicate prevention and approvals, not just the interface.

  6. 06

    Your data never trains a model

    Customer content is used to do your work and nothing else.

Audit

A record you can hand to an auditor.

  • Security event log

    Security-relevant events are recorded in a log your administrators can review.

  • Access reviews

    Review who can reach which workspaces and records, so access stays matched to the people who need it.

  • Record and version history

    Surface records keep their history, documents track authorship of every change, and versions can be compared.

Compliance status

Where we are, stated plainly.

We would rather tell you exactly where our program stands than overstate it.

SOC 2 readiness program

In progress

Our SOC 2 program is underway. Controls are mapped and monitored continuously in Vanta ahead of our SOC 2 audit. We are not SOC 2 certified today, and we will walk your security team through current status during evaluation.

Designed for GxP work

In place

Documents keep their Word fidelity and tracked authorship, records keep their history, and consequential steps wait for human review. How Sofie is qualified for your intended use remains a decision for your quality system, and we support that assessment.

Evidence, not advice

In place

Sofie summarizes and cites evidence from official sources and your own documents. It does not provide legal or regulatory advice; decisions stay with your qualified experts.

Questions

Frequently asked

Is our data shared with other customers?

No. Each customer runs in its own AWS environment with a dedicated VPC, private application and database subnets and an encrypted database. There is no shared tenancy.

Is our data used to train AI models?

No. Customer content is used to do your work and nothing else. No model is trained on it.

Are you SOC 2 certified?

Not yet. Our SOC 2 readiness program is underway, with controls mapped and monitored continuously in Vanta ahead of the audit. We will share progress with your security team during evaluation.

Can Sofie send email or change records on its own?

Not by default. Sending, sharing, calendar writes and updates to connected systems pause for human approval, including in scheduled work. Pre-approvals are optional and expire.

Which identity providers do you support?

SAML single sign-on with Okta, OneLogin, JumpCloud and Auth0, plus Okta, Microsoft Entra ID and Google sign-in, with passkey MFA and step-up verification before sensitive actions.

How do external partners get access?

By invitation only. Guests see only the Surfaces and records their invitation covers, with a role you choose, and invitations expire.

Does Sofie give regulatory advice?

No. Sofie summarizes and cites evidence from official sources and your documents. Decisions stay with your qualified experts.

Bring your security team
to the first session.

We will walk your security, IT and quality reviewers through the deployment architecture, identity controls, approval model and our SOC 2 program status, and work through your security questionnaire with you.