trust

What we have, and what we don't.

The whole vendor-review answer on one page, including the parts that lose us deals. If a control matters to you and it is missing here, we do not have it.

01

What we do not have

Stated first, because it is what you came to find out.

SOC 2
No report. Not in progress at a date we would be willing to print.
ISO 27001
No certification.
HIPAA
No BAA. Do not put protected health information in Solipsis.
FedRAMP
No authorisation.
Security audit
No published third-party cryptographic audit or penetration test.
Self-hosting
Not offered. You cannot run Solipsis on your own infrastructure.
Data residency
United States only. No EU region.
Open source
The client is not published, so you cannot verify the build yourself.
Mobile apps
No native iOS or Android app. The web app installs to a home screen.
If your procurement process requires SOC 2 or a signed BAA, Solipsis will fail it today. We would rather you learn that here than three weeks into an evaluation.
02

What we do have

Encryption
End-to-end on every plan. Keys are generated and held on your devices.
Identity
Device-bound. Stolen credentials alone decrypt nothing.
Two-factor
Authenticator apps and hardware passkeys, enforceable workspace-wide with a deadline.
Single sign-on
SAML 2.0 with your own provider — Okta, Entra ID, Google Workspace. Enterprise.
Directory sync
SCIM 2.0 provisioning and deprovisioning. Enterprise.
Audit log
Metadata-only record of administrative actions. Studio and above.
Retention
Scheduled destruction of ciphertext older than a period you set. Studio and above.
Data processing
A DPA covering GDPR, UK GDPR and CCPA, with Standard Contractual Clauses.
Disclosure
A published subprocessor list and Law Enforcement Guidelines.
Research
A good-faith security research safe harbour. Report to [email protected].
03

Where your data physically is

Everything runs in the United States. There is no other region to choose.

LayerProviderSees
ApplicationOVHcloud (OVH US LLC)Request logs, IP addresses
Database, storage, realtimeSupabaseCiphertext, public keys, membership
DNS, CDN, admin accessCloudflareTraffic in transit
PaymentsStripeBilling details. Cards never touch our servers
Transactional emailPostmarkEmail addresses, invite and receipt copy

None of them can decrypt your content, for the same reason we cannot: the keys were never uploaded to any of them.

04

How long things are kept

Your content
Until you delete it, or your retention rule destroys it. Gone from backups within 30 days.
Account records
While the account is active. Purged from backups within 30 days of deletion.
Server logs
Up to 90 days.
Support email
Up to 24 months.
Billing records
Up to 7 years, because tax law says so.
05

The awkward one: legal hold

Solipsis can be told to destroy things. A workspace owner can set ciphertext to be purged on a schedule, and can arm a switch that erases the workspace if nobody signs in for a set number of days.

Those features exist because some teams genuinely need data to stop existing. They also sit badly against a litigation hold, which requires you to preserve it.

We are not going to pretend that tension away. If your organisation is subject to preservation obligations, leave the retention rule off and the switch unarmed — both are off by default and neither can be enabled by anyone other than the owner.

We cannot implement a legal hold on your behalf. We cannot read your content well enough to know what is responsive to one, which is the same property that makes the rest of this page true.
06

Questions

Are you SOC 2 compliant?

No. There is no SOC 2 report for Solipsis, and we will not imply one is imminent. What we offer instead is a documented architecture in which the operator cannot read customer content at all.

Will you sign a BAA for HIPAA?

No. Solipsis is not a HIPAA business associate and should not be used for protected health information.

Can we host Solipsis ourselves?

No. There is no self-hosted distribution. The closest equivalent is that your encryption keys are already exclusively yours — the part of self-hosting most teams actually want.

Can our data stay in the EU?

Not today. All processing is in the United States, and we rely on Standard Contractual Clauses for transfers from the EEA, UK and Switzerland.

Who are your subprocessors?

OVHcloud, Supabase, Cloudflare, Stripe and Postmark, all in the United States. The current list is published and versioned on our Subprocessors page.

What do you do when law enforcement asks for data?

We respond to valid legal process with what we actually hold: account records and metadata. We cannot produce plaintext content, and doing so would require re-engineering the software on our users' devices.