Skip to content
Copiara

Security

Last updated: July 30, 2026

Draft, not final

Draft. This document is a placeholder while Copiara is pre-launch. It is not a contract, it has not been reviewed by counsel, and it will be replaced with a reviewed version before the first customer goes live. If you need current terms in the meantime, write to hello@copiara.com.

Copiara is pre-launch, and we would rather tell you plainly what is true today than gesture at compliance we do not have yet. Here is our current posture, and where it is headed.

Certifications

We do not hold a SOC 2 report today. One is planned as we move from pilots toward general availability. We have not claimed, and will not claim, a penetration test or a compliance attestation we have not actually completed.

Hosting and encryption

The product is hosted on a major cloud provider. Data is encrypted in transit and at rest, using the encryption the platform provider supplies by default.

Tenant isolation

Copiara is multi-tenant. Isolation is enforced at the query layer: every tenant-scoped query is filtered by tenant as a matter of course, not left to be remembered case by case.

Auditability

Every state change, a quote approved, a price overridden, an order placed, is written to an audit log. Role-based access controls who can take which action, spend limits and approval routing govern who can commit the business to what, and any support access to a customer’s account is read-only and itself audit-logged.

Talk to us

If your procurement or security team wants to send us a questionnaire ahead of a pilot, we welcome it. Reach us at hello@copiara.com and we will answer honestly, including where we are not there yet.