Review the contractual commitments for customer-data use and model training, including third-party model processing, retention, and deletion. Retention and deletion periods are set per organization on request. Use the approved security documentation and your agreement for the terms that apply.
Data use · Model providers · Retention
Hosting, encryption, and key management
Samaya hosts production data and backups exclusively in Google Cloud US regions. Request the encryption and key-management specifications for the proposed deployment. Review storage, network controls, and key ownership with your information security team.
Encryption · Key management · US residency
Permissions and source access
Research access is scoped to the user and authorized sources. Licensed providers can impose additional restrictions on MCP and API access. Validate each connector’s permission mapping during setup; personal connections require organization approval.
Access control · Source entitlements
Agent execution and MCP access
Multi-step agent work runs in a sandbox hosted in Samaya’s cloud environment. MCP connects approved assistants such as Claude or ChatGPT to Samaya research for Excel, Outlook, PowerPoint, or Word. Access uses your existing single sign-on, scoped tools, and enabled sources. The assistant’s tools and permissions determine the available actions; source-provider restrictions still apply.
Agent sandbox · MCP access
Security documentation and diligence
Request current SOC 2 documentation and independent-testing materials through the trust center. Confirm the scope, report period, and controls relevant to the service you will use.
Trust center · Current diligence documentation
Work through the requirements with us.
See how Samaya handles a research question relevant to your team.