Built to keep your customers' information safe.
Saphen handles your leads' names, contact details and conversations. Here's how we protect them.
Data separated per business
Every record belongs to one business, and the database itself refuses to show one business's data to another (row-level security), not just the app.
Encryption
All traffic uses HTTPS. Data is encrypted at rest by our database provider. Google Calendar connection tokens are additionally encrypted by Saphen before they're stored.
Least-privilege calendar access
Saphen asks Google only for permission to see when you're busy (never your event details) and to manage the events it books.
Verified connections
Messages from Stripe and our email and texting providers are checked for a valid signature before Saphen acts on them.
Roles
Owners, staff and view-only users. Only the account owner can change billing.
Human review
The Saphen team reviews every new business before it can message anyone, and can pause any business immediately.
Where your data lives
Saphen runs on established providers, each used for one job. They process data on our behalf under their own security programs.
| Provider | Used for |
|---|---|
| Vercel | Hosting the Saphen app and this website |
| Supabase | Database and sign-in |
| Anthropic | AI that drafts messages and understands replies |
| Resend | Sending and receiving email |
| Twilio | Sending and receiving text messages |
| Stripe | Payments and billing |
| Calendar (only if you connect it) |
What Saphen is not for
Saphen is not designed for protected health information and is not HIPAA compliant. Please don't use it to collect medical details, payment card numbers or government ID numbers from your customers.
Report a security issue
If you believe you've found a vulnerability, email hello@saphen.ai with “Security” in the subject. Please give us a reasonable chance to fix it before telling anyone else. See also our privacy policy.