What we have, and what we don't.
The whole vendor-review answer on one page, including the parts that lose us deals. If a control matters to you and it is missing here, we do not have it.
What we do not have
Stated first, because it is what you came to find out.
- SOC 2
- No report. Not in progress at a date we would be willing to print.
- ISO 27001
- No certification.
- HIPAA
- No BAA. Do not put protected health information in Solipsis.
- FedRAMP
- No authorisation.
- Security audit
- No published third-party cryptographic audit or penetration test.
- Self-hosting
- Not offered. You cannot run Solipsis on your own infrastructure.
- Data residency
- United States only. No EU region.
- Open source
- The client is not published, so you cannot verify the build yourself.
- Mobile apps
- No native iOS or Android app. The web app installs to a home screen.
What we do have
- Encryption
- End-to-end on every plan. Keys are generated and held on your devices.
- Identity
- Device-bound. Stolen credentials alone decrypt nothing.
- Two-factor
- Authenticator apps and hardware passkeys, enforceable workspace-wide with a deadline.
- Single sign-on
- SAML 2.0 with your own provider — Okta, Entra ID, Google Workspace. Enterprise.
- Directory sync
- SCIM 2.0 provisioning and deprovisioning. Enterprise.
- Audit log
- Metadata-only record of administrative actions. Studio and above.
- Retention
- Scheduled destruction of ciphertext older than a period you set. Studio and above.
- Data processing
- A DPA covering GDPR, UK GDPR and CCPA, with Standard Contractual Clauses.
- Disclosure
- A published subprocessor list and Law Enforcement Guidelines.
- Research
- A good-faith security research safe harbour. Report to [email protected].
Where your data physically is
Everything runs in the United States. There is no other region to choose.
| Layer | Provider | Sees |
|---|---|---|
| Application | OVHcloud (OVH US LLC) | Request logs, IP addresses |
| Database, storage, realtime | Supabase | Ciphertext, public keys, membership |
| DNS, CDN, admin access | Cloudflare | Traffic in transit |
| Payments | Stripe | Billing details. Cards never touch our servers |
| Transactional email | Postmark | Email addresses, invite and receipt copy |
None of them can decrypt your content, for the same reason we cannot: the keys were never uploaded to any of them.
How long things are kept
- Your content
- Until you delete it, or your retention rule destroys it. Gone from backups within 30 days.
- Account records
- While the account is active. Purged from backups within 30 days of deletion.
- Server logs
- Up to 90 days.
- Support email
- Up to 24 months.
- Billing records
- Up to 7 years, because tax law says so.
The awkward one: legal hold
Solipsis can be told to destroy things. A workspace owner can set ciphertext to be purged on a schedule, and can arm a switch that erases the workspace if nobody signs in for a set number of days.
Those features exist because some teams genuinely need data to stop existing. They also sit badly against a litigation hold, which requires you to preserve it.
We are not going to pretend that tension away. If your organisation is subject to preservation obligations, leave the retention rule off and the switch unarmed — both are off by default and neither can be enabled by anyone other than the owner.
Questions
Are you SOC 2 compliant?
No. There is no SOC 2 report for Solipsis, and we will not imply one is imminent. What we offer instead is a documented architecture in which the operator cannot read customer content at all.
Will you sign a BAA for HIPAA?
No. Solipsis is not a HIPAA business associate and should not be used for protected health information.
Can we host Solipsis ourselves?
No. There is no self-hosted distribution. The closest equivalent is that your encryption keys are already exclusively yours — the part of self-hosting most teams actually want.
Can our data stay in the EU?
Not today. All processing is in the United States, and we rely on Standard Contractual Clauses for transfers from the EEA, UK and Switzerland.
Who are your subprocessors?
OVHcloud, Supabase, Cloudflare, Stripe and Postmark, all in the United States. The current list is published and versioned on our Subprocessors page.
What do you do when law enforcement asks for data?
We respond to valid legal process with what we actually hold: account records and metadata. We cannot produce plaintext content, and doing so would require re-engineering the software on our users' devices.