See the new personalized Statt, built around your work and Intelligence Learn more.

Your Protected Policy Intel

Statt is built for organizations that can’t compromise on security. Your data stays yours, is isolated
from others, and is never used to train shared models.

Enterprise-Grade Security & Privacy

ownership

Encryption & zero-trust architecture

TLS in transit, AES-256 at rest, least-privilege by default, and segmented services on secure, cloud-native infrastructure.

encryption

Identity & access security

SSO/SAML, MFA, RBAC with granular permissions, IP allow-listing, and complete audit logs.

identity

Compliance & assurance

SOC 2 and ISO 27001 certifications; regular third-party audits and penetration tests.

Compliant with Industry Standards

AICPA
ISO

Clear Promises

Model providers we use must adhere to Zero Data Retention.

Role-based permissions and workspace separation keep teams and matters scoped.
Every action is traceable through audit logs.

FAQs

How does Statt define customer data?
At Statt, we distinguish between customer data and customer content. Customer data refers to documents or files that customers upload to the Statt platform. Customer content includes user queries submitted to Statt and the platform’s responses. Neither is used for model training.
We apply enterprise-grade security and privacy controls across every layer of our platform: (1) Encryption: All data is encrypted both in transit and at rest; (2) Access control: We enforce strict role-based permissions and follow the principle of least privilege; (3) No training on your data: By default, Statt never uses customer data for model training or improvement; (4) Secure partners: All subprocessors and external model providers are required to meet equivalent security and privacy standards. Additionally, each customer’s environment is logically isolated to prevent any data overlap or unauthorized access.
On secure, cloud-native infrastructure (Microsoft Azure) in environments certified for ISO 27001 and SOC 2.
We enforce role-based access control (RBAC) and logical workspace separation to ensure that only authorized individuals can access specific customer data. Customers maintain control over: (1) What data they upload; (2) How long it is retained; and (3) Whether it can be shared within their organization.
Statt strictly prohibits any training on customer data — both internally and by external providers. We only use your data to process your authorized requests. All model partners must adhere to Zero Data Retention (ZDR) policies, ensuring that no data is stored or reused beyond the scope of your request.
Scroll to Top