Trust & Legal
Promises are easy. Architecture is permanent. Sarthy enforces trust the same way it enforces alignment, in the code, not the contract.
Sarthy installs on your own infrastructure. Single container, Postgres, Redis. Your knowledge base, audit log, and all content live on your server. We have no production access to your install.
Direct messages between people are never alignment-processed. Enforced at five separate layers:
History cannot be rewritten. The audit log is append-only at the schema level (no UPDATE permission to the table, even for admins). Every state-changing action emits an audit event. Backed by SQLite WAL with daily backups to MinIO.
Least-privilege by default. The RBAC matrix is enforced server-side, not just in the UI. Every query is scoped by the requester's role and project access. Wiki pages, search results, and Ask Sarthy responses all respect the user's accessible paths.
Half-built code cannot land on main. The Open-Card Merge Lock ensures every related card closes before a feature merges. Architectural, not policy. A determined developer cannot bypass it under pressure.
Provider-agnostic abstraction. V1 ships Claude and OpenAI adapters. Your LLM calls go directly from your server to your chosen provider. No Sarthy intermediary, no Sarthy logging of LLM content, no Sarthy access to your provider keys (they live encrypted on your server with install-kek).
Found a security issue? Email security@sarthy.io with a description and any reproduction steps. We acknowledge within 24 hours, triage within 72 hours, and coordinate disclosure with you. No bounty programme yet; we're a small company. We'll credit you publicly if you'd like.
Do not report security issues through GitHub issues or the demo form. Use the email above.
Sarthy is built to support SOC 2, ISO 27001, and GDPR audit requirements through Module 22 (Compliance Evidence Export). Sarthy itself is not currently SOC 2 or ISO 27001 certified; certifications are on the roadmap as we scale. The architecture is designed to satisfy auditors when your install is in scope of those certifications.
Bring your security team
Twenty minutes. We install Sarthy on your server and open every architectural choice, layer by layer. Bring questions, bring auditors, bring the InfoSec team.
Book a demo