Skip to content
Legal

Data Security & Confidentiality Statement

Effective Date: September 14, 2026Last Updated: September 14, 2026

This statement explains, in plain terms, how Sharpe Group, Inc. protects client data and keeps SAGE conversations confidential. It describes the measures actually in place — not aspirations, certifications, or standards we have not implemented.

Encryption and access controls

All traffic between your browser and the platform is encrypted in transit using HTTPS/TLS, with certificates issued and renewed automatically. The site is not served over unencrypted connections.

The database and internal services are not reachable from the public internet. Only the web layer is exposed; everything behind it is accessible only from within the private server environment.

Payment credentials are entered directly with Stripe and never reach Sharpe Group, Inc. systems. Owner Portal session tokens are held in cookies that JavaScript cannot read, are restricted to this site, and are transmitted only over HTTPS.

Sharpe Group, Inc. does not claim compliance with any specific security certification or audited standard, and this statement should not be read as asserting one.

Confidentiality of SAGE conversations

Your organization’s SAGE conversations are not shared with, or visible to, other Sharpe Group, Inc. clients. Access is limited to your own account and to Sharpe Group, Inc. staff on an as-needed support basis.

Data retention

SAGE conversation history may remain available while the subscription is active and for up to 90 days after cancellation, subject to limited legal, security, billing, backup, or compliance requirements. Users may request earlier deletion of their conversation history or account data. See our Privacy Policy for full detail.

Third-party processors

Four external providers are involved in operating the platform. Each receives only what its specific function requires, and none has access to your account beyond that.

  • OpenAI — processes SAGE queries.
  • Stripe — payment processing and recurring billing.
  • Resend — transactional email delivery.
  • Hetzner — hosting and data storage, in Ashburn, Virginia, USA.

OpenAI does not use data submitted through the API to train its models by default under its business API terms. OpenAI may temporarily retain API interactions for safety and operational purposes in accordance with its API data usage policies.

Employee and subcontractor access

Access to production client data is limited to Sharpe Group, Inc. administrator accounts. Ordinary customer accounts can reach only their own data; there is no intermediate role that can view another client’s information.

Administrators access client data only where needed to deliver support, resolve a billing or access problem, or meet a legal obligation. Administrative actions on customer records — including deletion of SAGE conversation history on request — are recorded in an internal audit log capturing who acted, what changed, and when.

Beyond the four service providers named above, Sharpe Group, Inc. does not grant subcontractors access to client data.

Reporting a security concern

If you believe your account has been accessed without authorization, or you have identified a security issue with the platform, contact support@sharpe-group.com. Please include enough detail for us to reproduce or locate the issue.

On becoming aware of a security incident affecting client data, Sharpe Group, Inc. will investigate, take steps to contain it, and notify affected clients as required by applicable law.