Identity and access
- Single sign-on through Auth0 by default, or your own identity provider over OIDC or SAML.
- SCIM provisioning keeps members and groups aligned with your directory.
- Role-based access control; approval tiers and reviewers are defined in policy.
Data handling
- Your Git repository remains the source of truth for skill content.
- Savant stores references to commits, evaluation results, release records, and audit events.
- Workspaces are tenant-isolated; access is always scoped to one workspace.
Provenance and release control
- Every skill version resolves to a commit, and every release to evaluated content.
- Release records are signed; promotion runs draft → staging → production under policy.
- Auto-pin on regression holds the prior version; rollback is one action.
Audit
- Changes, approvals, releases, and access events are recorded append-only.
- Audit events can be exported to your SIEM.
Bounded improvement
- Run telemetry is redacted and pseudonymized before analysis; capture level follows your tenant setting.
- The optimization worker holds no database, Git, or release credentials.
- Locked sections of a skill cannot be read or changed by the optimizer.
- Only authorized people approve a recommendation. There is no autonomous deployment mode.
Reporting a vulnerability
Email security@savant.app. For security questionnaires, a DPA, or architecture reviews during procurement, contact sales@savant.app.