Everything Sledge does to protect your data
This is where the detail lives: the assessments Sledge holds, the documents your security team will ask for, how Sledge handles your data topic by topic, and the third parties that touch it. Every claim here is one the security team has confirmed is true today.
Compliance achievements
Every assessment Sledge earns stacks up security points. Select any program for its scope, status and report.
Documents
The security program
What Sledge does, topic by topic. No pass/fail grid โ Sledge will add one when a monitoring tool actually verifies each control continuously.
Infrastructure security
- AES-256 encryption at rest, TLS 1.2+ in transit
- Data scoped to your organization, with least-privilege access
- Private networking, managed firewalls and DDoS protection
- Hosted in established enterprise cloud data centers
Every byte you store in Sledge is encrypted the moment it lands and stays encrypted at rest. Production runs inside private networks with no direct public access, in established enterprise cloud data centers.
- Keys managed by a dedicated key-management service with rotation
- Encrypted, geographically redundant backups
- Hardened, regularly patched server images
- Infrastructure-as-code with peer-reviewed changes
- Segregated staging and production environments
- DDoS mitigation and WAF at the network edge
Data and privacy
- Retention and deletion procedures established
- Deleted on request per GDPR and CCPA
- Data classification policy enforced
- Never sold or used to train third-party models
Your data is yours. Sledge never sells it and never uses it to train third-party AI models. You decide how long it is kept and can export or delete it on request, in line with GDPR and CCPA.
- Data Processing Addendum available on request
- Documented data retention schedule
- Right to access, export and erasure honored
- Data minimization โ we collect only what we need
- Privacy reviews for new features
Payments and billing
- Card payments handled by a specialist payment provider
- Card numbers never touch Sledge servers
- Tokenized, vaulted payment methods
- Fraud monitoring on every transaction
Payments are processed by a specialist payment provider. Your full card number never touches Sledge servers โ we only ever see a secure token, so there is nothing sensitive for us to lose.
- 3-D Secure and strong customer authentication
- Tokenized cards stored in the processor vault, not Sledge
- Real-time fraud and anomaly monitoring
Authentication and accounts
- SSO and SAML for enterprise accounts
- Enforced MFA and strong password policy
- Managed, industry-standard auth provider
- Session, device and audit logging
Sign-in is handled by a managed identity platform with enterprise SSO, SAML and enforced multi-factor authentication. Every session, device and admin action is logged so you always know who did what.
- SCIM provisioning and de-provisioning
- Role-based access control with granular permissions
- Configurable session timeouts
- Full authentication audit trail
Product security
- CASA Tier 2 assessment against OWASP ASVS
- Annual third-party penetration testing
- Continuous dependency and code scanning in CI/CD
- Secure SDLC with mandatory peer review
Security is built into how we ship. Sledge has completed a CASA Tier 2 assessment against the OWASP ASVS, runs annual third-party penetration tests, and scans every code change and dependency before it reaches production.
- Mandatory peer review on all code
- Automated static and dependency scanning in CI/CD
- Secrets scanning to prevent leaked credentials
- Responsible disclosure program
- Remediation SLAs by severity
Continuous monitoring
- 24/7 threat detection and alerting
- Centralized, automated log analysis
- Documented, tested incident response plan
- Automated backups and point-in-time recovery
We watch our systems around the clock. Centralized logs feed automated detection and alerting, and a documented, regularly tested incident response plan means we react fast when something looks off.
- On-call rotation with defined escalation paths
- Point-in-time recovery and tested restores
- Post-incident reviews with corrective actions
- Uptime and status published publicly
- Anomaly detection on access patterns
Availability and resilience
- Runs across multiple availability zones
- Automated daily backups with point-in-time recovery
- 99.9% uptime target with a public status page
- Continuity and disaster recovery plans tested regularly
Sledge runs across multiple availability zones, so a single failure does not take your jobs offline. Backups run daily with point-in-time recovery, uptime is published, and the continuity and recovery plans are tested rather than filed away.
- Tested restores, not just scheduled backups
- Documented recovery time and recovery point objectives
- Live status page for incidents and maintenance
- Redundant, geographically separated storage
AI controls
- Your data never trains third-party models
- Human review of AI-suggested actions
- Scoped, least-privilege access for AI processing
- AI providers held to the same data standards
Sledge uses AI to remove busywork, not to expose your data. Your information is never used to train third-party models, AI access is scoped to the minimum needed, and consequential actions stay under human review.
- AI subprocessors bound by the same data terms
- No training on customer data, contractually enforced
- Audit trail on AI-assisted actions
- Clear indication when AI is involved
Organizational security
- Background checks on personnel
- Annual security and privacy training
- Enforced MFA on all internal systems
- Vendor security review before onboarding
People and process are part of security too. Sledge runs background checks on personnel, requires annual security and privacy training, enforces MFA on internal systems, and reviews every vendor before onboarding.
- Least-privilege internal access, reviewed regularly
- Formal onboarding and offboarding procedures
- Written security policies reviewed annually
- Confidentiality obligations for all staff
Subprocessors
Who processes your data on Sledge's behalf, and where.Cloud hosting and storage
Your data is stored in the United States, encrypted, on an established cloud provider that runs its own audited security program.
- Data
- Encrypted application data and backups
- Region
- United States
Database and sign-in
Your account and sign-in details are held in the United States by a managed database and authentication provider.
- Data
- Account records and sign-in credentials
- Region
- United States
Application hosting and delivery
The Sledge app is served from infrastructure in the United States.
- Data
- App delivery and request logs
- Region
- United States
AI processing
Anything you send to an AI feature is processed in the United States and is not used to train third-party models.
- Data
- Content you send to AI features
- Region
- United States
Payments
Payments run through a specialist payment provider. Your full card number never reaches Sledge servers.
- Data
- Billing details and payment methods
- Region
- United States
Email and messaging delivery
Notifications Sledge sends on your behalf are delivered by providers in the United States.
- Data
- Notification and message delivery
- Region
- United States
Last reviewed August 2026. The full named list is available on request โ .
Frequently asked questions
No. Sledge does not sell your data, does not hand it to advertisers, and does not use it to train third-party AI models. Your data is in Sledge to run your business.
Bank connections run through a regulated payments provider, so Sledge never stores your bank passwords and never holds a full card number. And no payment leaves your account until a person on your team approves it.
Fiona works inside your companyโs Sledge account, using a defined set of tools. She reads and drafts on her own. Anything that leaves your company โ sending to an outside party, moving money, publishing something public โ stops and waits for a person on your team to approve it.
Yes. Ask and Sledge deletes your data. Email security@getsledge.com and the security team will handle it.
In the United States, on established cloud providers that run their own independently audited security programs. It is encrypted while it travels and while it is stored.
Yes. Sledge completed a CASA Tier 2 assessment through TAC Security, an App Defense Alliance authorized lab, which checked the Sledge app against the OWASP Application Security Verification Standard. Passing that assessment is required by Google for access to Google user data. It is not a Google endorsement of Sledge.
Ask through the Trust Center, or email security@getsledge.com. Sledge takes the request, a person on the security team reviews it, and they follow up.
Yes. The subprocessor register in the Trust Center shows what each provider does, what data it touches, and where it runs. The full named list is available on request.
Didn't find your answer?
Ask and a person on the Sledge security team will answer. Questions go to Sledge, not to an analytics tool.
This Trust Center was last reviewed on August 20, 2026. Sledge shows a date, not a live verification indicator, because no monitoring tool drives one yet.
Run your back office on software you can vouch for
Independently assessed. No contracts. No setup fees.


