Security
SOC 2 on every plan, HIPAA with a BAA on Enterprise. You set what the AI can read, write, or delete, and who sees the results.
Three places to run it. The dashed box is the boundary your data stays inside.
Papercrane Cloud
Free and Pro
For most teams. Nothing to set up.
Where the AI runs
Your own isolated environment on infrastructure we run, in US regions.
Your credentials
Encrypted in our vault. Decrypted only for the query that needs them.
Network
Our environment reaches your sources over encrypted connections. Nothing to install on your side.
Model provider
Anthropic and Google, under terms that exclude training on your data.
Compliance and sign in
SOC 2. Google and Microsoft sign in.
Enterprise hosted
Enterprise
For organizations that need dedicated infrastructure, including HIPAA work.
Where the AI runs
Dedicated, locked down VMs we run for you, in US regions. Your own cloud project on request.
Your credentials
Encrypted inside your VM. Decrypted only for the query that needs them.
Network
Outbound denied except to an allowlist. Private connectivity to your data.
Model provider
Your choice: Vertex, Bedrock, or Anthropic and OpenAI direct.
Compliance and sign in
SOC 2. HIPAA with a BAA. Enterprise SSO.
Enterprise BYOC
Enterprise BYOC
For organizations whose data can't leave their cloud.
Where the AI runs
In your AWS, Azure, or GCP account, as containers or in your Kubernetes cluster.
Your credentials
In your secrets store. We never hold them.
Network
Outbound only, to us. No inbound ports, no peering, no PrivateLink.
Model provider
Your own provider account. Your terms with the model vendor apply.
Compliance and sign in
SOC 2. HIPAA with a BAA. Enterprise SSO.
Need a closed network, with no outbound connection at all?
Talk to usThese don't change with where it runs.
Credentials encrypted, used only at query time
Disconnect a source and its credential is deleted.
Read, write, delete rules per integration
Let the AI read Salesforce but never delete a contact. Keep QuickBooks read only.
How access rules workEvery call logged
Who asked, what was called, what was passed, and when. Scheduled runs write the same entries.
What the log recordsSharing you control
Open link, verified emails, team only, or embedded with a separate view per customer. Revoke any time.
Sharing optionsGoogle and Microsoft sign in
Owner, admin, and member roles once people are in. Enterprise SSO on Enterprise.
Encrypted in transit and at rest
TLS on every Papercrane endpoint. Secrets in the cloud provider's secret manager.
SOC 2 Type II certified and HIPAA compliant.
HIPAA compliance comes through a BAA, signed on request. The SOC 2 report, HIPAA documentation, and our policies are shared as part of your security review. Encryption in transit and at rest, secrets in the cloud provider's secret manager, least privilege staff access, monitoring, and a written incident response plan, with the evidence for each in the same place. Report a vulnerability at security@papercrane.ai.
A 30 minute call with an engineer. Bring your reviewer, your questionnaire, and your policy.
Flat pricing, not per viewer. See pricing