Security is our top priority

Highsail employs best-in-class procedures and practices to ensure that your data remains private, secure, and compliant.


Secure user
and contract data

Highsail's user and contract data is protected by AES-256, the industry-standard encryption algorithm. Additionally, strict identity and access management policies (such as single sign-on and two-factor authentication) ensure client data remains protected at all times.

Privacy by
design

Highsail was designed for GDPR in partnership with Deloitte. Our GDPR trajectory has been thoroughly reviewed – resulting in the creation of a well-defined set of deliverables that are future proof when it comes to data privacy.

Compliance

Leading international standards for information security management? No problem! All infrastructure, people, and technologies critical to the confidentiality, integrity, availability, and privacy of all data managed by Highsail is in progress of getting both SOC 2 compliant and ISO 27001 certified.

Risk Management

Not only does Highsail run a company-wide risk management program based on the SOC 2 and ISO 27001 standards – we also partner with leading vendors to go above and beyond: from running internal, educational phishing programs to continuous penetration testing.


Reliance

Highsail's services are built on industry-leading technologies such as Amazon Web Services (AWS) to ensure the highest grade security of client data and best-in-class scalability. We pride ourselves in our uptime (99.99% in the last year).

Your data remains
private

Given the sensitive nature of customer data, our data centers only store text snippets (no entire contracts). Further, we don’t allow any AI technologies associated with our add-on (eg. Azure OpenAI Service) to store nor use any (customer) data.

FAQ - General & Security

How can I learn more about how Highsail integrates with systems?

What happens when a customer connects their systems database to Highsail?

Can I set up Highsail so users will have to authenticate through SSO?

Language agnostic: how does it work?

Does Highsail store my company's data for training purposes?

How can I get a hold of Highsail's Data Processing Agreement (DPA)?

How can I learn more about how Highsail integrates with systems?

What happens when a customer connects their systems database to Highsail?

Can I set up Highsail so users will have to authenticate through SSO?

Language agnostic: how does it work?

Does Highsail store my company's data for training purposes?

How can I get a hold of Highsail's Data Processing Agreement (DPA)?