Skip to main content
Saturation

Production finance software with security at every layer.

Saturation covers budgeting, banking, bill pay, p-cards, and approval flows. All of it protected with SOC 2, encryption in transit and at rest, and funds held at FDIC-insured partner banks.

SOC 2 Type 2 CertifiedSOC 1 Type 1 CertifiedTLS 1.2+ in Transit, AES-256 at RestRole-Based Access and Enterprise SSOAudit Trail Behind the Number

Commitment to your security.

At Saturation, we prioritize your data security. We've designed our systems not just to streamline your work, but to do so while safeguarding your data.

SOC 1 Type 1.

Where SOC 2 covers data security, SOC 1 covers financial controls. The audit independently verified that Saturation's controls over budgets, actuals, production banking, contractor payments, and cost reporting are properly designed: the standard studios, enterprise clients, and financial auditors require when a platform is handling their money.

SOC 2 Type 2.

A SOC 2 Type 2 examination goes further than confirming controls are designed correctly. An independent CPA firm tested Saturation's controls across a sustained period and confirmed they operated effectively throughout it, not just on the day an auditor looked. The examination covered the Security category of the Trust Services Criteria, which governs access, authentication, change management, encryption, monitoring, and incident response across the platform. Saturation holds both SOC 2 levels, and full reports are available under NDA at security@saturation.io.

Data protection.

Your data is paramount. All information transmitted to and from Saturation is encrypted in transit with TLS 1.2 or higher, and AES-256 at rest. Our Information Security Policy underpins our dedication to data protection, and we regularly conduct risk assessments to identify and mitigate potential threats.

Privacy first.

We deeply respect your privacy. Client data remains confidential and is only accessed as necessary to provide our services. We do not share client data unless required to perform the required services.

AI processing.

AI features in Saturation send your prompts and content to a small set of enterprise AI providers we contract with directly. Those providers do not train their public models on your data, and they do not retain prompts beyond the request itself.

The full list of AI providers we use is on our sub-processor page.

Secure User Authentication
We use Google Authentication for secure sign-ins, harnessing Google's formidable security measures to reduce password-related risks. Your pre-existing Google account's security settings are used for this purpose.
Continuous Monitoring
Our systems are under 24/7 surveillance. Any unusual activity triggers an immediate investigation. Regular reviews, tests, and audits ensure compliance with our security policy.
Shared Responsibility
We encourage all users to take proactive steps towards their data's security, such as using strong, unique passwords and practicing safe sharing.

Reliable infrastructure.

Saturation is built on Render, a trusted platform that automatically encrypts data in transit and at rest. Render employs high-security protocols such as network isolation and traffic encryption. They comply with globally recognized certifications like SOC 2 and GDPR.

At the edge, every saturation.io request is served over HTTPS with HSTS preload eligibility, and a strict Content Security Policy restricts which script and frame origins the browser will load.

IT controls and practices.

We are enforcing multi-factor authentication (MFA) to enhance security. We apply MFA to all accounts on internal applications and third-party services, such as cloud providers. Key IT policies and baseline standards ensure that all devices and services adhere to our security standards, from deployment to end-of-service.

We engage independent third parties to perform application penetration testing on an annual cadence, and run continuous vulnerability scanning between assessments.

Backup and continuity.

Production data is continuously replicated, with point-in-time database recovery and automated snapshots taken throughout the day. Backups are retained across multiple availability zones so a regional incident never means lost work — your budgets, approvals, and ledger remain restorable through wrap and well past it.

Ongoing improvements.

Our commitment to security is unwavering. We're continuously refining our security measures to ensure uncompromised data integrity. Our Information Security Policy is regularly updated to align with evolving business operations and security risks.

Responsible disclosure

Found a vulnerability? Tell us.

Security researchers are an important part of how we keep production data safe. Send us reproduction steps and we'll acknowledge within two business days.

Security questions, answered.

Common questions from production teams, studios, accountants, bond companies, and financiers evaluating Saturation.

Yes. Saturation has completed a SOC 2 Type 2 examination performed by an independent CPA firm, which tested both the design and the operating effectiveness of our controls across the examination period. It covered the Security category of the AICPA Trust Services Criteria. A SOC 2 report is a restricted-use document rather than a public certificate, so the full report is shared under NDA. Request it via security@saturation.io.

Yes. Saturation holds SOC 1 Type 1 certification, which covers internal controls over financial reporting. Where SOC 2 addresses how the platform protects your data, SOC 1 addresses whether the financial reporting built on that data can be relied on, which is the standard studios, financiers, and their auditors look for. SOC 1 Type 2 is on our roadmap. The full report is available under NDA via security@saturation.io.

Access is strictly role-based. Only users you authorize can see your production's data, and permissions are scoped to what each role actually needs. Production office, finance, leadership, and outside reviewers do not inherit the same access. Enterprise plans also support SSO for centralized identity governance.

All data transmitted to and from Saturation is encrypted in transit with TLS 1.2 or higher, and stored at rest with AES-256 encryption. We build on Render, a platform that enforces network isolation and traffic encryption and holds its own SOC 2 and GDPR certifications.

AI features send your prompts and content to a small set of enterprise AI providers we contract with directly. Those providers do not train their public models on your data, and they do not retain prompts beyond the request itself. The full list of AI providers is on our sub-processor page at /legal/subprocessors.

Production data is continuously replicated with point-in-time database recovery and automated snapshots taken throughout the day. Backups are retained across multiple availability zones so a regional incident never means lost work — budgets, approvals, and ledger entries remain restorable through wrap and well past it.

Email security@saturation.io with reproduction steps. We acknowledge reports within two business days and follow RFC 9116 disclosure metadata, published at /.well-known/security.txt.

Yes. Approvals, exports, and financial record changes are logged so that controllers, auditors, and bond companies can trace what happened, who did it, and when. This is not a bolted-on feature. It is core to how the system is designed for production finance.

Yes. Funds are held at FDIC-insured partner banks, not directly by Saturation. Your money is stored with the same safeguards used by traditional financial institutions and is protected up to applicable limits.

Our systems are monitored 24/7. Any unusual activity triggers an immediate investigation. We enforce multi-factor authentication across internal applications and third-party services, conduct annual third-party penetration testing, and run continuous vulnerability scanning between assessments.

Yes. Role-based permissions let you give studios, financiers, and bond companies exactly the visibility they need for oversight and audit purposes, without opening up the full production finance environment to everyone.

Your production data is only accessible to users you explicitly authorize. Saturation employees may access your financial data solely for troubleshooting or active support cases, and never for any other purpose. Any such access requires a documented reason, is logged under our SOC 2 controls, and is limited to what is strictly necessary to resolve the issue at hand. Outside of those circumstances, your budgets, bills, transactions, and approval history are not visible to our team. Your data is yours.

The most common questions cover the access model, encryption standards, audit trail completeness, MFA enforcement, AI data handling, backup posture, and the banking infrastructure underneath the product. If your team needs a direct security review rather than a landing page, we can walk through the full control posture with them.

Your production data deserves this level of care.

Saturation is built for productions that can't afford a breach. SOC 2 Type 2 certified, encrypted in transit and at rest, and auditable from first dollar to final wrap.

Security | Saturation.io