Casper

Security

Office of the CEO work is among the most confidential material in an enterprise. Casper is built so that content stays in your dedicated tenant, is processed only under Zero Data Retention contracts, and is never used to train foundation models.

No foundation model training

Customer content is never used to train or fine-tune Casper models or underlying foundation models. Enterprise contracts with Anthropic and OpenAI include Zero Data Retention (ZDR).

Dedicated customer cloud

Each enterprise customer runs on an isolated stack — separate application deploy, database, and LLM API organizations. We do not co-mingle OCEO data on a shared multi-tenant database.

Encryption

All traffic uses TLS 1.2+. Data at rest is encrypted via the cloud database provider (AES-256). Customer-managed keys (BYOK) are available as an enterprise upsell.

Identity & access

Enterprise tenants authenticate via SSO (SAML/OIDC through WorkOS) with MFA enforced in WorkOS AuthKit or the corporate IdP. Role-based controls govern kill switch, invites, export, and offboarding. Optional IP allowlisting for board-level tenants.

Audit & kill switch

Security-relevant actions are audited without storing prompt bodies. Workspace admins can halt all LLM egress instantly via the kill switch.

Retention & deletion

Configurable retention for chats and audit logs. On contract end, customers can export their data and request hard deletion of the dedicated workspace.

Our access to your data

Casper engineers do not access customer workspace data by default. Support access requires your explicit written approval and is recorded as a break-glass audit event.

Compliance

Product controls ship first. SOC 2 Type II is tracked as a parallel program (control checklist available to diligence reviewers). Ask your Casper contact for the subprocessors list, DPA outline, and current audit status.

Back to Casper · Enterprise sign-in