How Sloper handles customer data.
The questions every security review asks first, answered before the paperwork.
Trained on your data?
No.
Customer data is never used to train the model.
Revision history?
Yes.
Core product records keep revision history a person can inspect.
Scoped to your organization?
Yes.
Organization access is enforced on every product-data request.
Human review before release?
Always.
An authorized person reviews work before it moves forward.
How data moves through Sloper.
Customer input
Files, standards, and setup selected for the pilot.
Access checked on every request
- Isolation boundary
Sloper processing and storage
Inputs become organization-scoped product records.
Temporary agent workspace
Agent work runs beside the record, never inside it, and is discarded after the turn.
Managed LLM gateway
Every model request routes through Sloper's gateway.No path to model training.
Human review gate
Reviewer
An authorized designer or technical designer checks the work before it moves forward.
Output
A reviewed export or versioned vendor release moves forward.
Versioned, with history
Who can see the work, and when it leaves.
Brand team
- Edit
- Review
- Approve
- Release
- Restore
The roles agreed for the pilot control who does what.
Administrators
- Membership
- Roles
- Access review
- Settings
Organization membership, roles, access review, and administrative settings stay under authenticated control.
Vendors
- Released work only
- Response path
Vendor access is limited to the work and response path the brand has released.
When the pilot ends, the data has a plan.
- Any time
Export what you need
The pilot defines the records, working outputs, and vendor packages the team can export.
- Before the pilot
Retention agreed up front
Active, post-pilot, and post-contract retention is agreed before work begins.
- On request
Deletion has a path
Deletion-request handling and the lifecycle of backup copies are documented during security review.
- If Sloper winds down
A close-out plan exists
The close-out plan covers access removal, export, retention, and deletion.
Running a security review? Start here.
Email us and we share the current documents. Everything below is ready to send.
- Security overview
- Subprocessor list
- DPA
- Architecture notes
- Questionnaire responses