One AI employee. Every team. The controls written down.
A company with a security team asks different questions before it hires: whose credentials, what audit trail, which standards, who else sees the data. This page answers them in the order they are usually asked, says which are in place, which are on request, and which are still on the roadmap, and tells you when not to buy.
- SOC 2 Type 2connection layer and hosting
- GDPRDPA on request
- CCPAno sale of personal data
- AES-256at rest, per workspace
- TLS 1.2+in transit, everywhere
An illustration of how the conversation reads, not a transcript from a client account.
Sanaf is one AI employee per workspace, hired into jobs. For a larger company that means one colleague every team can hand work to in Slack or Microsoft Teams, with a written job description per job, sign-ins scoped per job and vaulted outside the model, approval rules per kind of action that get stricter when nobody is watching, isolation between workspaces at the database, and a log of everything it did. Encryption, hosting and the connection layer hold SOC 2 today; our own audit and SAML single sign-on are on the roadmap, and we say so.
Everything security, IT and procurement ask. With a status.
In the order they are usually asked. Green is in place today. Purple is a document or a term you ask for. Amber is on the roadmap, and we will not promote it early.
Credentials never touch the AI
Sign-ins happen through OAuth where the app supports it, scoped to the job. Keys are encrypted at rest, injected at call time by the connection layer, and never written into a prompt, a chat or the log. The model asks for an action; the connection layer signs the request.
Approval policies per kind of action
Not one switch. Each kind of action is set to do it, ask first, or never, with conditions, and the rules can be stricter when the employee is unattended. Anything irreversible waits for a linked manager by default.
A full work log
Every action, every approval, every credential use and what each piece of work cost, in a log a manager reads in the channel or the console. Mistakes are found in the log rather than reconstructed afterwards.
Workspace isolation
Each workspace is isolated at the database with row-level rules, and the runtime role cannot read across them. Nothing learned in one workspace reaches another.
No training on your data
Your conversations, documents and connected data are never used to train a model, ours or a provider’s. Model calls go through one gateway to named providers under terms that say the same.
Encryption in transit and at rest
TLS for every connection and AES-256 at rest, per workspace, on the hosting and database platforms named on the security page.
SOC 2 Type 2
Held by the connection layer that holds your credentials and by the hosting and database platforms, each with a public trust page the security page links to. Our own SOC 2 audit is planned; until it is complete we will not claim it.
A data processing agreement
Ask and we will send our DPA, the subprocessor list from the security page, and the trust pages of the platforms we run on. GDPR and CCPA obligations are met, and we will say plainly which standards we hold ourselves and which we do not.
Linked managers and admin roles
Only the people you link as managers can approve a held action, from Slack, Teams or the console. Workspace admins control which apps are connected, which jobs are live, and how far each is promoted.
SAML single sign-on and SCIM provisioning
Sign in to the console is with Google or a code sent to email today. SAML and automatic provisioning for larger tenants are on the roadmap. If either is a requirement, tell us before you commit to anything.
A choice of data region
Data is hosted in the United States on the platforms named on the security page. We do not offer a choice of region yet; if your obligations require data to stay in a specific jurisdiction, raise it with us first.
Invoicing, terms and a named contact
Self-serve is prepaid credit bought by card, with nothing recurring. For a company that needs an annual agreement, invoicing on terms and a person to write to, the fully managed hire on the pricing page is quoted to the role in writing and invoiced directly.
The full compliance table, the subprocessor list and the data-handling detail are on the security page. Last updated 2026-09-02.
One team, one job, shadow first. Then the next team.
The way a larger company hires Sanaf is the way a small one does, repeated. Nobody rolls out to every team on day one, and the log from the first team is what convinces the second.
- 1
One team picks one job
Usually the team with the clearest pile: the support queue, the renewals, the invoices. The job description is already written; the team edits it in plain English.
- 2
IT approves the connections
Each app is a sign-in scoped to that job, listed with its scopes, revocable on its own. Nothing is connected that the job does not need.
- 3
A shadow week
It drafts, the team reads, the rules are tuned. Nothing leaves until a manager promotes that kind of action.
- 4
Promote, then widen
The team promotes actions one kind at a time. When the log reads the way they want, the next team hands over its job, on the same employee, with its own rules.
- 5
The log is the report
What it did, what it asked, and what each piece of work cost, per job, per team, per month. There is no separate ROI dashboard to build; the log is the number.
The same colleague, holding a different job for each team.
Support, sales, marketing, operations, finance and people each hand it their own job with their own rules. One employee, one memory, one log, and a bill for the work rather than a seat for every person who might mention it.
Named providers, through one gateway, under your rules.
Which AI models does it use, can we choose, and what reaches them: the three questions every security review asks, answered.
Named providers, one door
Model calls go to named providers through a single gateway, so the list of who sees what is short and written on the security page. Your data trains none of them.
Cost matched to the task
Routine work runs on smaller, cheaper models; reasoning runs on the larger ones. The work log shows what each piece of work used, so there is no separate meter to watch.
Injection treated as content
Everything a tool returns, an email, a document, a web page, is treated as information to read, never as orders to obey. The actions someone would want to hijack are the ones already behind your approval.
When not to buy.
A comparison you cannot trust is worthless, and so is an enterprise page that never says no. These are the cases where we would tell you to wait or to choose someone else.
- SAML single sign-on or SCIM provisioning is a hard requirement today, not a nice-to-have. It is on our roadmap, and we will not pretend otherwise.
- Your data must stay in a jurisdiction other than the United States. We do not offer a choice of region yet.
- You need a vendor holding its own SOC 2 or ISO 27001 report this quarter. The platforms we run on hold theirs; ours is planned.
- You want several named agents per team with per-user permissions, rather than one employee with scoped logins of its own. That is a different design, and some of the products on our comparison pages do it well.
- The work is mostly one person driving an assistant in the moment. A per-seat assistant is the better buy for that.
Start on the self-serve plans. Move to a managed hire when you need terms.
Every plan carries every control on this page. The managed hire adds the people: someone who learns the role, sets it up with your team, and stays on.
- Every approval rule, the shadow period, the work log and workspace isolation, on every tier
- Credit in plain dollars for the work, not per seat, from $20 and never expiring, with a free start
- A DPA, the subprocessor list and the platforms’ trust pages, on request
- The fully managed hire: role interview, connections and rules set with your team, a shadow week, a weekly report, and a person to write to
- Invoiced directly on terms, quoted to the role in writing