SamoeSAMOE
Security & trust

Your business data stays yours · we just connect in to help

Samoe connects to your existing systems via MCP · we don't siphon your data elsewhere. Everything is encrypted, role-based, and auditable. The details are all below.

What we have in place

Security you can verify, not just claim

Your data is never used to train AI

Your data is used only to do your work. We never use it to train models, never share it across customers, and never sell it. The agents operate on your data in isolation.

Encryption in transit & at rest

Every connection uses TLS 1.2+. Stored data is encrypted with AES-256.

Automated backups

Daily encrypted backups with point-in-time recovery on supported plans.

Hosted in the ASEAN region

Infrastructure runs in enterprise-grade ASEAN data centres · close to you and aligned with Thai law.

PDPA-aligned

Designed around Thailand's PDPA, with a Data Processing Agreement (DPA) available.

Role-based access (RBAC)

Control who sees and does what, down to module and branch. SSO on the Enterprise plan.

Auditable activity log

Every action · by a person or an agent · is logged with who, what, and when, fully reviewable.

Compliance roadmap

Where we are, and what's next

Straight from me · what's done, what's underway, and what's still planned.

Live
  • TLS / AES-256 encryption
  • RBAC + audit log
  • Automated backups
  • PDPA-aligned + DPA
In progress
  • Enterprise SSO
  • Configurable data retention
  • Security docs for procurement
On the roadmap
  • Third-party security certification
  • Penetration-test reports

Have a security question?

Need a DPA or details for procurement or IT? Email our security team directly.