ModelCharter

Is Sana SOC 2 compliant?

Yes

Sana Labs · Productivity

Yes. Sana Labs holds a SOC 2 report covering Sana, which gives independent assurance over its security controls.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

SOC 2 report
Confirmed
Sana Labs reports a SOC 2 attestation. Request the current report and relevant bridge letter during procurement.
ISO 27001
Confirmed
Sana Labs also reports ISO/IEC 27001 certification.
Default data training
No by default
Sana states no customer data is used to train its or third-party LLMs, and AI subprocessors are contractually barred from training on it.
Business-tier training
No by default
Enterprise (single-tenant deployment, SAML and SCIM, DPA) is the business tier recorded for this profile.
Practical risk: Sana states it does not train models on customer data, holds SOC 2 and ISO 27001, and publishes a subprocessor list and DPA. HIPAA BAA availability and a firm EU data-residency guarantee are not documented publicly, so confirm both before handling PHI or EU-restricted data.

How to make a decision

Check the precise account tier, written contract and intended data before approving Sana. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Sana

See the full Sana risk profile, with every data-handling fact and its source, or browse all rated AI tools.