Skip to content

How Sloper handles customer data.

The questions every security review asks first, answered before the paperwork.

  • Trained on your data?

    No.

    Customer data is never used to train the model.

  • Revision history?

    Yes.

    Core product records keep revision history a person can inspect.

  • Scoped to your organization?

    Yes.

    Organization access is enforced on every product-data request.

  • Human review before release?

    Always.

    An authorized person reviews work before it moves forward.

How data moves through Sloper.

  1. Customer input

    Files, standards, and setup selected for the pilot.

    Access checked on every request

  2. Isolation boundary

    Sloper processing and storage

    Inputs become organization-scoped product records.

    Temporary agent workspace

    Agent work runs beside the record, never inside it, and is discarded after the turn.

    Managed LLM gateway

    Every model request routes through Sloper's gateway.No path to model training.

  3. Human review gate

    Reviewer

    An authorized designer or technical designer checks the work before it moves forward.

  4. Output

    A reviewed export or versioned vendor release moves forward.

    Versioned, with history

Who can see the work, and when it leaves.

  • Brand team

    • Edit
    • Review
    • Approve
    • Release
    • Restore

    The roles agreed for the pilot control who does what.

  • Administrators

    • Membership
    • Roles
    • Access review
    • Settings

    Organization membership, roles, access review, and administrative settings stay under authenticated control.

  • Vendors

    • Released work only
    • Response path

    Vendor access is limited to the work and response path the brand has released.

When the pilot ends, the data has a plan.

  1. Any time

    Export what you need

    The pilot defines the records, working outputs, and vendor packages the team can export.

  2. Before the pilot

    Retention agreed up front

    Active, post-pilot, and post-contract retention is agreed before work begins.

  3. On request

    Deletion has a path

    Deletion-request handling and the lifecycle of backup copies are documented during security review.

  4. If Sloper winds down

    A close-out plan exists

    The close-out plan covers access removal, export, retention, and deletion.

Running a security review? Start here.

Email us and we share the current documents. Everything below is ready to send.

  • Security overview
  • Subprocessor list
  • DPA
  • Architecture notes
  • Questionnaire responses