SAINT
Trust · protection, privacy and reporting

Trust needs a visible exit.

SAINT limits authority, asks before consequential outward action, and keeps receipts. This page states what protects your information, who may see it, and how to report a problem.

No independent security certification is claimed. SAINT has not completed external penetration testing or a published audit against the final saleable configuration. Controls that exist are described as such; the rest is labelled as release work. No system is risk-free.
01

What protects your information

Data is encrypted in transit and at rest. Access to connected services uses scoped credentials that can be revoked without touching the rest of the account. Devices carry their own identity, consequential events are recorded as audit entries, and operator access is restricted.

Independent verification of these controls, and the published subprocessor register naming every provider and location, remain release requirements before commercial launch.

02

Who can see what you capture

Specialist providers handle hosting, communications, speech processing and AI inference. They receive only what their task needs and are bound by contract. Human access at SAINT is limited to what you consent to, to security investigation, or to legal compliance.

SAINT does not sell personal data and does not use it for behavioural advertising. Production settings and provider contracts are intended to prevent your content being used to train general-purpose models; that control must still be contractually verified before launch, and it is stated here as an obligation rather than a finished proof.

03

Least authority, and a receipt for what is done

Security and privacy are the same boundary here. Saint holds the narrowest permission that makes a feature work, asks again before an outward action such as sending, buying or committing, and leaves a receipt you can inspect afterwards. Voice alone is not treated as sufficient record of a consequential act.

The full account of what is handled, why, how long it is kept and how to inspect, correct, export or erase it is in the privacy notice. Erasure is self-serve. Cookie and analytics choices are on the cookie choices page.

04

Report a vulnerability

Email hello@sa-nt.com with the subject ‘Security report’, affected surface, observed behavior, reproduction steps and impact. Do not access another person’s data, persist beyond the minimum proof, degrade the service or publish sensitive details before SAINT can assess them.

05

Account or phone compromised

Contact support, revoke relevant provider sessions, secure the email and mobile number connected to the account, and tell SAINT which channel or device is affected. SAINT may pause outward actions while identity and authority are re-established.

06

A device is missing

The planned production lifecycle requires owner-bound claims, fresh authenticated sessions and revocation for lost, returned or compromised units. The instrument is not production hardware today; these controls remain subject to integrated verification.

Open lost or stolen help →

07

What not to send

Never email passwords, payment-card details, private signing material, one-time recovery codes or unnecessary personal content. A report may be moved to a more suitable protected channel after initial contact.

For a data-protection request rather than a security report, write to privacy@sa-nt.com.