This overview is informational. Your order form, Business Associate Agreement, Zero Data Retention Agreement, and other signed terms control if they differ from this page.
Compliance status
SOC 2 audit-ready
MSPilot’s security program is designed and operated against the SOC 2 Trust Services Criteria. Our controls and evidence are audit-ready. The next milestone is an independent examination, after which the SOC 2 report will be available.
HIPAA-compliant deployments
MSPilot supports HIPAA-compliant deployments. We accept Protected Health Information only under a signed Business Associate Agreement and through the services and configurations covered by that agreement.
Zero data retention
Zero-data-retention terms are available for eligible deployments. Prompt and completion content is not retained after processing when ZDR applies.
Regional deployment
Customer environments can be deployed in the United States, Canada, the United Kingdom, or Australia.
Security controls
MSPilot operates safeguards appropriate for a multi-tenant cloud service, including:- Multi-factor authentication for sensitive systems
- Role-based access control and least privilege
- Tenant isolation and authorization boundaries
- Encryption in transit and at rest
- Security and audit logging
- Vulnerability scanning and remediation
- Incident response procedures
- Tested backups and recovery procedures
- Vendor and subprocessor risk management
- Secure data retention and disposal processes
AI data handling
MSPilot does not use Customer Data to train third-party foundation models and does not sell Customer Data. We maintain written zero-data-retention terms with Microsoft Azure AI Foundry and Anthropic for the applicable services and resources. An MSP’s data-retention configuration is documented in its agreement with MSPilot.- Zero data retention
- Optional AI analytics
- HIPAA
Prompt and completion content is processed to return a response and is not retained after the request is fulfilled. MSPilot may retain operational metadata needed to authenticate, secure, meter, support, and audit the service.
HIPAA safeguards
For BAA-covered deployments:- MSPilot acts as a Business Associate, or as a subcontractor to a Business Associate, for PHI processed through the services defined in the BAA.
- PHI is limited to approved services and configurations.
- Microsoft Azure and Anthropic are engaged under written business associate terms for the applicable services.
- Prompt and completion content is not used for model training.
- Access, security, incident response, breach notification, and secure disposal obligations are documented in the BAA.
- Customers remain responsible for using only approved workflows and for meeting their own HIPAA obligations.
Data residency
MSPilot supports deployments in:🇺🇸 United States
Deploy customer environments in a supported United States region.
🇨🇦 Canada
Deploy customer environments in a supported Canadian region.
🇬🇧 United Kingdom
Deploy customer environments in a supported United Kingdom region.
🇦🇺 Australia
Deploy customer environments in a supported Australian region.
Privacy and data rights
Our Privacy Policy explains what personal data we collect, why we process it, how we share it, and the rights available to individuals. You can request access, correction, export, or deletion of personal data by emailing support@mspilot.io. When MSPilot processes data on behalf of an MSP, we coordinate with that MSP to support the request.Service providers
MSPilot uses service providers for infrastructure, AI inference, analytics, monitoring, and other operational functions. The current Privacy Policy is the source of truth for our public subprocessor disclosures. Current disclosed providers include Microsoft Azure, Vercel, Cloudflare, Anthropic, Microsoft Azure AI Foundry, PostHog, and Sentry.Security documentation
Customers and prospective customers can request security materials, subject to appropriate confidentiality requirements. Available materials may include:- Security questionnaires
- Architecture and data-flow information
- Security and privacy policies
- Control descriptions and supporting evidence
- Penetration-test information
Legal resources
Privacy Policy
Review how MSPilot collects, uses, protects, and shares personal data.
Terms of Service
Review the terms governing use of MSPilot.
Cookie Policy
Review the cookies and similar technologies used by MSPilot.
Contact MSPilot
Ask about compliance, security, privacy, BAAs, or retention options.
Frequently asked questions
Is MSPilot SOC 2 compliant?
Is MSPilot SOC 2 compliant?
MSPilot’s security program is designed and operated against the SOC 2 Trust Services Criteria, and we consider the environment audit-ready. The next milestone is an independent examination. We will make the resulting SOC 2 report available when that process is complete.
Can MSPilot process PHI?
Can MSPilot process PHI?
Yes, but only after both parties sign a BAA and confirm the applicable services, models, region, and configuration are covered.
Does MSPilot train models on Customer Data?
Does MSPilot train models on Customer Data?
No. MSPilot does not use Customer Data to train third-party foundation models.
Can we choose our retention period?
Can we choose our retention period?
Yes. Retention is agreed with each MSP. Eligible deployments can use zero data retention, while other deployments can retain prompt and completion content for an agreed period when the MSP requests AI-usage analytics.
How do HIPAA retention settings differ?
How do HIPAA retention settings differ?
BAA-covered deployments do not retain prompt or completion content for analytics. MSPilot retains only operational metadata and logs needed for usage, security, and HIPAA audit evidence.