Skip to content
Legal

Trust & security

How the Soika platform is designed to be operated inside regulated environments.

This page summarises current practice and is provided for information. Have it reviewed by counsel in each operating jurisdiction before it is treated as a binding published policy.

Deployment boundary

Soika deploys into your own infrastructure: private cloud, on-premise, sovereign cloud or fully air-gapped. There are no outbound telemetry callbacks or external licence checks required for the platform to run.

Identity and access

OIDC and SAML single sign-on, SCIM provisioning, and role-based access control down to individual models, agents, tools and datasets. Service-to-service traffic is authenticated with mTLS.

Auditability

Every model invocation, retrieval, tool call and agent decision is written to an immutable audit log with the identity that triggered it. Fleet runs can be replayed step by step.

Data protection

Configurable retention and redaction policies, PII detection, and residency enforcement applied at the routing layer so requests cannot cross a jurisdiction boundary.

Reporting a vulnerability

Please report suspected security issues to hello@soika.ai. We acknowledge reports within two business days.

Questions about this page? Write to hello@soika.ai.