Skip to main content
MSPilot gives managed service providers a governed way to deploy AI across client environments. This page summarizes the safeguards, contractual options, and deployment choices available to MSPilot customers.
This overview is informational. Your order form, Business Associate Agreement, Zero Data Retention Agreement, and other signed terms control if they differ from this page.

Compliance status

SOC 2 audit-ready

MSPilot’s security program is designed and operated against the SOC 2 Trust Services Criteria. Our controls and evidence are audit-ready. The next milestone is an independent examination, after which the SOC 2 report will be available.

HIPAA-compliant deployments

MSPilot supports HIPAA-compliant deployments. We accept Protected Health Information only under a signed Business Associate Agreement and through the services and configurations covered by that agreement.

Zero data retention

Zero-data-retention terms are available for eligible deployments. Prompt and completion content is not retained after processing when ZDR applies.

Regional deployment

Customer environments can be deployed in the United States, Canada, the United Kingdom, or Australia.

Security controls

MSPilot operates safeguards appropriate for a multi-tenant cloud service, including:
  • Multi-factor authentication for sensitive systems
  • Role-based access control and least privilege
  • Tenant isolation and authorization boundaries
  • Encryption in transit and at rest
  • Security and audit logging
  • Vulnerability scanning and remediation
  • Incident response procedures
  • Tested backups and recovery procedures
  • Vendor and subprocessor risk management
  • Secure data retention and disposal processes
We review these controls and their supporting evidence as the platform and its risk profile evolve. No internet-connected service can guarantee absolute security.

AI data handling

MSPilot does not use Customer Data to train third-party foundation models and does not sell Customer Data. We maintain written zero-data-retention terms with Microsoft Azure AI Foundry and Anthropic for the applicable services and resources. An MSP’s data-retention configuration is documented in its agreement with MSPilot.
Prompt and completion content is processed to return a response and is not retained after the request is fulfilled. MSPilot may retain operational metadata needed to authenticate, secure, meter, support, and audit the service.
Do not submit PHI before a BAA is signed and the applicable MSPilot services, models, region, and configuration are confirmed as in scope.

HIPAA safeguards

For BAA-covered deployments:
  • MSPilot acts as a Business Associate, or as a subcontractor to a Business Associate, for PHI processed through the services defined in the BAA.
  • PHI is limited to approved services and configurations.
  • Microsoft Azure and Anthropic are engaged under written business associate terms for the applicable services.
  • Prompt and completion content is not used for model training.
  • Access, security, incident response, breach notification, and secure disposal obligations are documented in the BAA.
  • Customers remain responsible for using only approved workflows and for meeting their own HIPAA obligations.
A signed BAA is required before PHI is submitted to MSPilot.

Data residency

MSPilot supports deployments in:

🇺🇸 United States

Deploy customer environments in a supported United States region.

🇨🇦 Canada

Deploy customer environments in a supported Canadian region.

🇬🇧 United Kingdom

Deploy customer environments in a supported United Kingdom region.

🇦🇺 Australia

Deploy customer environments in a supported Australian region.
Provider capabilities and the customer’s selected models can affect regional processing. Confirm residency requirements with MSPilot before submitting regulated or sensitive data.

Privacy and data rights

Our Privacy Policy explains what personal data we collect, why we process it, how we share it, and the rights available to individuals. You can request access, correction, export, or deletion of personal data by emailing support@mspilot.io. When MSPilot processes data on behalf of an MSP, we coordinate with that MSP to support the request.

Service providers

MSPilot uses service providers for infrastructure, AI inference, analytics, monitoring, and other operational functions. The current Privacy Policy is the source of truth for our public subprocessor disclosures. Current disclosed providers include Microsoft Azure, Vercel, Cloudflare, Anthropic, Microsoft Azure AI Foundry, PostHog, and Sentry.

Security documentation

Customers and prospective customers can request security materials, subject to appropriate confidentiality requirements. Available materials may include:
  • Security questionnaires
  • Architecture and data-flow information
  • Security and privacy policies
  • Control descriptions and supporting evidence
  • Penetration-test information
Email support@mspilot.io with your organization, use case, and requested materials.

Privacy Policy

Review how MSPilot collects, uses, protects, and shares personal data.

Terms of Service

Review the terms governing use of MSPilot.

Cookie Policy

Review the cookies and similar technologies used by MSPilot.

Contact MSPilot

Ask about compliance, security, privacy, BAAs, or retention options.

Frequently asked questions

MSPilot’s security program is designed and operated against the SOC 2 Trust Services Criteria, and we consider the environment audit-ready. The next milestone is an independent examination. We will make the resulting SOC 2 report available when that process is complete.
Yes, but only after both parties sign a BAA and confirm the applicable services, models, region, and configuration are covered.
No. MSPilot does not use Customer Data to train third-party foundation models.
Yes. Retention is agreed with each MSP. Eligible deployments can use zero data retention, while other deployments can retain prompt and completion content for an agreed period when the MSP requests AI-usage analytics.
BAA-covered deployments do not retain prompt or completion content for analytics. MSPilot retains only operational metadata and logs needed for usage, security, and HIPAA audit evidence.
Last updated: September 10, 2026.