ContractSphere is built for the industry with the least tolerance for security theater. Here is exactly how your data is protected, where it lives, and who can touch it.
Deployment models
Multi-Tenant SaaS. A shared platform we operate in our Azure environment. Every customer’s contract content, embeddings, and decision logs are logically isolated and encrypted per tenant, and document processing runs in isolated, ephemeral jobs — no customer can reach another’s data. Fastest to start: live in days, not weeks. Product-fit evaluations run here on a small, anonymized contract set, which is deleted if the customer does not continue.
Bring Your Own Cloud (BYOC). The application runs inside your own Azure subscription — your network, your keys, your access policies, your monitoring. Functionally the security posture of an on-prem deployment, with the operating model of SaaS. Your security perimeter is the perimeter.
The BYOC access model
In a BYOC deployment, WorkMesh operates the application through customer-granted, scoped roles. There is no standing access to contract content. Every access grant is logged and revocable by the customer at any time, and all human access is governed by the customer's identity provider.
BYOC also answers the question every buyer should ask an early-stage vendor: what happens to us if something happens to you? The deployment, the data, the embeddings, and the decision logs live in your subscription. They are yours on day one and they remain yours in every scenario — continuity is architectural, not contractual.
Controls
- Encryption: in transit (TLS 1.2+) and at rest.
- Single sign-on: Okta, Microsoft Entra, and Google Workspace.
- Provisioning: SCIM 2.0.
- Access control: role-based access control with least-privilege administration.
- Operations: vulnerability management and an incident response process, maintained as administrative, physical, and technical safeguards per our Data Processing Addendum.
Data & AI
Contract content, embeddings, and model traffic are never used to train third-party models. In BYOC deployments, model traffic stays within the customer's subscription boundary.
What runs under the hood
ContractSphere uses OpenAI models delivered through Azure OpenAI Service — no consumer AI endpoints, no third-party API calls outside Azure. In Bring Your Own Cloud deployments, the Azure OpenAI resource is provisioned inside your own Azure subscription: model traffic never leaves your tenant, your Microsoft agreement governs the resource, and your team can see every model call in your own Azure logs. In Multi-Tenant SaaS, the same architecture runs under our subscription with per-tenant isolation. In both models, prompts, contract content, and embeddings are not used to train foundation models — Azure OpenAI's no-training guarantee applies, and we add no exceptions.
Sub-processors
The current sub-processor table is published in our Privacy Policy.
Audit & evidence
Every intake produces an immutable decision log: who reviewed, what was flagged, what the human decided, when, and against which playbook version. We respond to security questionnaires and provide documentation of our security controls in every evaluation.
Contact
Security questions and reports: security@contractsphere.ai.