Security
Your environment.Your data.Your decisions.
Every customer runs Sofie in its own isolated AWS environment, with enterprise sign-in, human approval for consequential actions and a record your quality and security teams can review.
Eight commitments, in every deployment.
These apply to every customer deployment.
An isolated deployment for every customer
Your own AWS environment: a dedicated VPC, private subnets and an encrypted database. Never shared.
Your data never trains a model
Customer content is used to do your work, and nothing else.
Enterprise sign-in
SAML SSO with Okta, Entra ID, Google and more, passkey MFA and configurable idle timeouts.
Human approval where it matters
Sending, sharing and unattended work pause for approval by default.
Evidence for every conclusion
Answers carry page-level citations; missing evidence is flagged, never invented.
Audit trail and access reviews
Security events, access reviews and record history you can hand to an auditor.
Governed memory
Admins decide what Sofie learns and retains, by user, team or site.
SOC 2 program underway
Controls mapped and monitored continuously ahead of our SOC 2 audit.
Isolated deployment
One customer, one environment.
Sofie is deployed privately for each customer. Your application, automation and database live in your own network on AWS, never alongside another customer’s.
Dedicated VPC
A separate virtual network per customer, with VPC flow logs.
Private subnets
Application and database tiers run in private subnets within that network.
Encrypted Aurora
Your data is stored in an encrypted Aurora PostgreSQL database of your own.
AWS Bedrock
Knowledge bases, embeddings and memory run on AWS Bedrock.

Your people
- SSO sign-in
- Passkey MFA and step-up
Your dedicated AWS environment
Single tenantDedicated VPC · flow logs enabled
Private application subnets
Private database subnets
AWS Bedrock
- Knowledge bases
- Embeddings and memory
Another customer’s environment: its own VPC, subnets and database
No shared tenancy
Identity & access
The right people, and only them.
Sign-in, session and permission controls your IT team already expects, applied to every workspace, document and Surface.
Single sign-on
SAML SSO with Okta, OneLogin, JumpCloud and Auth0, plus Okta, Microsoft Entra ID and Google sign-in. Email magic links where SSO is not in place.
Passkey MFA with step-up
Passkeys as a second factor, with a fresh check before sensitive actions.
Idle timeout you set
Sessions end after a period of inactivity you choose, from 15 minutes to 24 hours (1,440 minutes).
Roles built from fine-grained permissions
Workspace owner, admin, editor and viewer roles built from 19 permissions, and organization-wide workspace roles for broader programs.
Guest access by invitation
External partners see only what their invitation allows, with Owner, Editor, Viewer or Responder access. Invitations last 14 days by default, up to a year.
Protected connections
OAuth tokens for connected systems are encrypted, and service-to-service calls are signed.
AI governance
Sofie drafts. People decide.
Anything consequential waits for a person. Everything Sofie concludes carries its evidence.

Sequence · Weekly supplier digest
Waiting for approvalSofie wants to
Send an email to 4 recipients
To supplier-quality@larkspurbio.com +3
Subject Approved suppliers: one new Form 483 posted
3 sources cited · draft attached
- 01
Human approval by default
Sending email, writing to calendars, updating Salesforce or Monday.com and posting to team messaging pause for a person to approve, including in unattended Sequences.
- 02
Pre-approvals that expire
Teams can pre-approve routine actions for a period. Pre-approvals are optional and expire.
- 03
Citations on every conclusion
Answers and drafts carry page-level citations. When the evidence is missing, Sofie names the gap instead of filling it from memory.
- 04
Governed memory
Administrators turn memory on or off by user, team or site. It never crosses organization boundaries and respects your retention window.
- 05
Server-checked actions
Actions on Surfaces run through server-enforced eligibility rules, duplicate prevention and approvals, not just the interface.
- 06
Your data never trains a model
Customer content is used to do your work and nothing else.
Audit
A record you can hand to an auditor.
Security event log
Security-relevant events are recorded in a log your administrators can review.
Access reviews
Review who can reach which workspaces and records, so access stays matched to the people who need it.
Record and version history
Surface records keep their history, documents track authorship of every change, and versions can be compared.
Compliance status
Where we are, stated plainly.
We would rather tell you exactly where our program stands than overstate it.
SOC 2 readiness program
In progressOur SOC 2 program is underway. Controls are mapped and monitored continuously in Vanta ahead of our SOC 2 audit. We are not SOC 2 certified today, and we will walk your security team through current status during evaluation.
Designed for GxP work
In placeDocuments keep their Word fidelity and tracked authorship, records keep their history, and consequential steps wait for human review. How Sofie is qualified for your intended use remains a decision for your quality system, and we support that assessment.
Evidence, not advice
In placeSofie summarizes and cites evidence from official sources and your own documents. It does not provide legal or regulatory advice; decisions stay with your qualified experts.
Questions
Frequently asked
Is our data shared with other customers?
No. Each customer runs in its own AWS environment with a dedicated VPC, private application and database subnets and an encrypted database. There is no shared tenancy.
Is our data used to train AI models?
No. Customer content is used to do your work and nothing else. No model is trained on it.
Are you SOC 2 certified?
Not yet. Our SOC 2 readiness program is underway, with controls mapped and monitored continuously in Vanta ahead of the audit. We will share progress with your security team during evaluation.
Can Sofie send email or change records on its own?
Not by default. Sending, sharing, calendar writes and updates to connected systems pause for human approval, including in scheduled work. Pre-approvals are optional and expire.
Which identity providers do you support?
SAML single sign-on with Okta, OneLogin, JumpCloud and Auth0, plus Okta, Microsoft Entra ID and Google sign-in, with passkey MFA and step-up verification before sensitive actions.
How do external partners get access?
By invitation only. Guests see only the Surfaces and records their invitation covers, with a role you choose, and invitations expire.
Does Sofie give regulatory advice?
No. Sofie summarizes and cites evidence from official sources and your documents. Decisions stay with your qualified experts.
Bring your security team
to the first session.
We will walk your security, IT and quality reviewers through the deployment architecture, identity controls, approval model and our SOC 2 program status, and work through your security questionnaire with you.