Casper
Security
Office of the CEO work is among the most confidential material in an enterprise. Casper is built so that content stays in your dedicated tenant, is processed only under Zero Data Retention contracts, and is never used to train foundation models.
No foundation model training
Customer content is never used to train or fine-tune Casper models or underlying foundation models. Enterprise contracts with Anthropic and OpenAI include Zero Data Retention (ZDR).
Dedicated customer cloud
Each enterprise customer runs on an isolated stack — separate application deploy, database, and LLM API organizations. We do not co-mingle OCEO data on a shared multi-tenant database.
Encryption
All traffic uses TLS 1.2+. Data at rest is encrypted via the cloud database provider (AES-256). Customer-managed keys (BYOK) are available as an enterprise upsell.
Identity & access
Enterprise tenants authenticate via SSO (SAML/OIDC through WorkOS) with MFA enforced in WorkOS AuthKit or the corporate IdP. Role-based controls govern kill switch, invites, export, and offboarding. Optional IP allowlisting for board-level tenants.
Audit & kill switch
Security-relevant actions are audited without storing prompt bodies. Workspace admins can halt all LLM egress instantly via the kill switch.
Retention & deletion
Configurable retention for chats and audit logs. On contract end, customers can export their data and request hard deletion of the dedicated workspace.
Our access to your data
Casper engineers do not access customer workspace data by default. Support access requires your explicit written approval and is recorded as a break-glass audit event.
Compliance
Product controls ship first. SOC 2 Type II is tracked as a parallel program (control checklist available to diligence reviewers). Ask your Casper contact for the subprocessors list, DPA outline, and current audit status.