Security

Compliant. Controllable. In your cloud.

SOC 2 on every plan, HIPAA with a BAA on Enterprise. You set what the AI can read, write, or delete, and who sees the results.

Papercrane Cloud

Free and Pro

Boundary: Papercrane

Your own isolated environment, one per workspace

Your data sources

Queried in place with access you approve

Papercrane agent

Runs in your environment, nothing shared with other customers

Dashboards

Rendered inside the environment

Queries, credentials, and results stay inside this box.

ENCRYPTED · ISOLATED PER WORKSPACE

Papercrane control plane

Orchestration, the UI, login

Enterprise hosted

Dedicated VMs

Boundary: Papercrane

Dedicated, locked down VMs we run for you

Your data sources

Private connectivity, queried in place

Papercrane agent

Outbound denied except to an allowlist. Custom model routing

Dashboards

Rendered inside the VM

Queries, credentials, and results stay inside this box.

ALLOWLISTED EGRESS · ENCRYPTED

Papercrane control plane

Orchestration, the UI, login

Enterprise BYOC

AWS, Azure, GCP

Boundary: You

Your cloud account: containers or Kubernetes

Your data sources

Credentials stay in your secrets store

Papercrane agent

Runs on your compute

Dashboards

Rendered in your cloud

Queries, credentials, and results stay inside this box.

OUTBOUND ONLY · 443 · NO INBOUND

Papercrane control plane

Orchestration, the UI, login

Three places to run it. The dashed box is the boundary your data stays inside.

Three ways to deploy.

Papercrane Cloud

Free and Pro

For most teams. Nothing to set up.

Where the AI runs

Your own isolated environment on infrastructure we run, in US regions.

Your credentials

Encrypted in our vault. Decrypted only for the query that needs them.

Network

Our environment reaches your sources over encrypted connections. Nothing to install on your side.

Model provider

Anthropic and Google, under terms that exclude training on your data.

Compliance and sign in

SOC 2. Google and Microsoft sign in.

Start free

Enterprise hosted

Enterprise

For organizations that need dedicated infrastructure, including HIPAA work.

Where the AI runs

Dedicated, locked down VMs we run for you, in US regions. Your own cloud project on request.

Your credentials

Encrypted inside your VM. Decrypted only for the query that needs them.

Network

Outbound denied except to an allowlist. Private connectivity to your data.

Model provider

Your choice: Vertex, Bedrock, or Anthropic and OpenAI direct.

Compliance and sign in

SOC 2. HIPAA with a BAA. Enterprise SSO.

Book a security review

Enterprise BYOC

Enterprise BYOC

For organizations whose data can't leave their cloud.

Where the AI runs

In your AWS, Azure, or GCP account, as containers or in your Kubernetes cluster.

Your credentials

In your secrets store. We never hold them.

Network

Outbound only, to us. No inbound ports, no peering, no PrivateLink.

Model provider

Your own provider account. Your terms with the model vendor apply.

Compliance and sign in

SOC 2. HIPAA with a BAA. Enterprise SSO.

How it works

Need a closed network, with no outbound connection at all?

Talk to us

Secure by default.

These don't change with where it runs.

Credentials encrypted, used only at query time

Disconnect a source and its credential is deleted.

Read, write, delete rules per integration

Let the AI read Salesforce but never delete a contact. Keep QuickBooks read only.

How access rules work

Every call logged

Who asked, what was called, what was passed, and when. Scheduled runs write the same entries.

What the log records

Sharing you control

Open link, verified emails, team only, or embedded with a separate view per customer. Revoke any time.

Sharing options

Google and Microsoft sign in

Owner, admin, and member roles once people are in. Enterprise SSO on Enterprise.

Encrypted in transit and at rest

TLS on every Papercrane endpoint. Secrets in the cloud provider's secret manager.

SOC 2 Type II certified and HIPAA compliant.

HIPAA compliance comes through a BAA, signed on request. The SOC 2 report, HIPAA documentation, and our policies are shared as part of your security review. Encryption in transit and at rest, secrets in the cloud provider's secret manager, least privilege staff access, monitoring, and a written incident response plan, with the evidence for each in the same place. Report a vulnerability at security@papercrane.ai.

Questions security reviewers ask

Bring your security review. We'll bring the answers.

A 30 minute call with an engineer. Bring your reviewer, your questionnaire, and your policy.

Flat pricing, not per viewer. See pricing