This page used to be long. It listed certifications, agreements and regional deployments, and a reader had no way to tell which of them existed. The short version is more useful, so this page says what is true today and names what is missing rather than leaving it out.
What is running
Nothing customer-facing. There is no hosted service accepting traffic right now: the API environment is shut down and self-service signup is closed. The only things live are this website and the developer documentation, both static.
When the service runs, it runs on Amazon Web Services in the US East region. Traffic reaches it over TLS. Nothing is served from a machine that is not AWS.
What has not been audited
There is no SOC 2 report. The only assessment that exists is an internal one, written in March 2026, which scored 9 of 36 controls as fully met — 0 of 4 on availability. It was not performed by an auditor, and no auditor has been engaged. A Type II report additionally requires a twelve-month observation window that has not started. Anyone who was told otherwise was told wrong.
There is no Business Associate Agreement. Sandstone Cloud cannot sign one, and KAPEX should not be used with protected health information. Earlier versions of this page listed a BAA under an enterprise tier. That was not accurate and it has been removed.
There has been no external penetration test and no third-party code audit.
What the software does with data
Deletion is real and not a flag. A delete request removes the record rather than hiding it, and the removal is written to a ledger so that it can be shown to have happened. Scoring and expiry never delete anything on their own: material that ages out is archived and cleared, never dropped silently.
Deployment is intended to be in the customer's own environment, so that memory data stays there. That is the design and the licence model; it is not something a reader should take on trust while nothing is running.
Reporting a vulnerability
Email support@sandstonecloud.com with "Security" in the subject. Please include enough detail to reproduce the issue. We will acknowledge within three business days.
There is no bug bounty programme and we are not offering payment. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it before publishing.
If you are evaluating KAPEX
Ask for the specific thing you need rather than a package. If an answer to a diligence question is not on this page, the honest answer is usually that the artifact does not exist yet, and we would rather say so than send you a document that implies it does. Write to support@sandstonecloud.com.