Skip to content

Security

Where your records live, who can see them and where our SOC 2 audit stands.

security@stepo.ai

The controls

What a reviewer can check

Where your data lives

United States hosting
AWS us-east-1, with application services in private subnets and no public database.
Encrypted at rest
The database is encrypted under a rotating AWS KMS key we manage. Secrets and files sit in encrypted storage, and backups are kept for 30 days.
Encrypted in transit
HTTPS on TLS 1.3 and 1.2, and TLS-only connections to the database.
Monitored
CloudTrail, GuardDuty, a web application firewall and alarms to on-call.

Who sees what

Separate organizations
Shared infrastructure, with database controls keeping each organization’s records apart.
Roles by feature and project
Use the built-in roles or build your own, then grant them for one project or the whole organization, with an optional expiry date.
Sessions you control
Revoke one session or all of them.
Single sign-on
Coming soon. Today login is email and password.

Your data and AI

Yours to take
Export observations with their photos, and keep every report as a PDF.
AI output is labeled
AI suggestions on a record are labeled as AI, and your team can change any of them. When someone changes the AI risk analysis, the original is kept.
Dictation is not kept
When you dictate into a field, the audio is deleted once it is transcribed.

Compliance

SOC 2 audit in progress
We are working with Vanta toward our SOC 2 report. Ask us for our security documentation.
A history of changes
Changes to compliance schedules, site groups and chemical records keep an audit history.

Bring your security review to the demo

Send us your questionnaire and we answer it ourselves before your first project.