The Intranet built for Google Workspace
Security
Steegle.One
Steegle.One the Google Sites intranet platform lives exclusively in your Google Workspace: this approach to security sets Steegle apart as a boutique provider of intranet services for organizations.
Built with Security in Mind
Built with Security in Mind
Built with Security in Mind
We understand that continuity of service is a primary concern for our clients, especially as a smaller, niche provider. That’s why we’ve built Steegle.One with security in mind from the very start. Our platform relies on gadgets that interact directly with your own Google domain, making it GDPR compliant and a great choice for organizations looking for compliance without going through a rigorous testing process.
Unlike other well known intranet platforms like Happeo or LumApps, we don’t replicate data to servers in different countries, ensuring that your data remains secure. We also don’t hold sensitive data like employee directories or reports of sensitive policies, giving you peace of mind. There’s no need for escrow agreements or other complex arrangements with us.
Privacy First in AI Search
How Steegle.One Keeps Data Secure
Our AI People Search is Private by Design. Unlike other intranet platforms that export your sensitive employee directories to external AI processors (like OpenAI or Anthropic), Steegle.One utilizes your own Google Workspace Gemini environment.
No API calls to third-party servers
No risk of your data training public Al models
Your data stays exactly where it belongs, inside your Google Workspace.
Ensuring Data Sovereignty
A Spotlight on Steegle.One's Unique Approach
In today's complex digital landscape, businesses rely heavily on intranet solutions to streamline communication, collaboration, and data management.
As concerns surrounding data sovereignty, ownership, and data portability rise, organizations must choose platforms that prioritize these principles. Steegle.One stands apart in the intranet market, offering a solution that intrinsically empowers data sovereignty and seamless user experience.
Minimizes security risks
Addresses compliance concerns
Protects the right to control access
Steegle.One:
Built on the Foundation of Google Workspace
Our core strength lies in seamless integration with Google Workspace. By leveraging Google’s robust infrastructure, all client data remains securely within their own Google environment. This means businesses retain complete ownership and control over their sensitive information, offering several advantages:
Google Workspace cloud compliance
GDPR and HIPAA compliance in Workspace
Zero Trust architecture for collaboration
IAM for Workspace login security
Not a Data Processor
Clients Keep Full Control of their Google Workspace Data
Because we don't hold sensitive data on any Steegle-owned system, Steegle is not a data processor in day-to-day operation and has no standing access to your data.
We do not access sensitive data. Your information stays in Google Workspace.
We do not store employee profiles, policies, or reports.
We do not require escrow or complex arrangements.
We are a safer choice for security-focused teams.
How We Build It
How access actually works, split into the two ways clients deploy Steegle.One.
Most Common
Standard install: zero access, ever
For most clients, our gadgets and applications are installed directly by your own Google Workspace admin, following our guided setup.
Steegle never touches your data at any point. There is no access to request, because there is nothing for us to access.
No employee directories or sensitive data held by Steegle
No escrow agreements or export processes needed
Right to erasure is trivial because everything is already in your own tenant
White-Glove Service
Full-service migration & build: temporary, scoped access
Clients who want us to handle data migration or hands-on configuration directly, rather than doing the install themselves, receive a fully managed build.
This requires temporary technical access to parts of your Google Workspace during the engagement, permissioned by you and limited to defined service windows.
Two-factor authentication enforced for every Steegle team member
Access scoped to the build window, not continuous or standing
No local copies. Nothing is downloaded outside your Workspace
Reliable Security with Google Workspace
At Steegle.One, we understand that security is a top priority for organizations. That's why we rely on Google's robust security measures. Google Workspace itself encrypts all data in transit using HTTPS and all data at rest using AES 128-bit encryption. It uses 2-factor authentication, and complies with various industry standards such as SOC 2, ISO 27001, and HIPAA.
GDPR
Data processing stays inside your own Workspace tenant by default.
GOOGLE WORKSPACE
HIPAA
Google Workspace offers a Business Associate Agreement for healthcare clients.
GOOGLE WORKSPACE
SOC 2 / ISO 27001
Certified security standards ensure compliance with SOC 2 and ISO 27001.
GOOGLE WORKSPACE
AES 128-bit Encryption
Client data is safeguarded with AES 128-bit encryption, providing strong protection.
GOOGLE WORKSPACE
FERPA
Student records remain under your institution’s control inside your own Workspace tenant.
STEEGLE PRACTICE
NYSED
Workspace supports compliance with NY Education Law 2-d.
STEEGLE PRACTICE
COPPA
Children’s data stays inside your own Workspace tenant under your control.
STEEGLE PRACTICE
CMMC Level 1
Foundational cyber hygiene controls are applied inside your tenant.
STEEGLE PRACTICE
PPRA
Student survey data stays inside your tenant under institutional control.
STEEGLE PRACTICE
NEN 7510 (Netherlands)
Safeguards for healthcare information remain tenant-controlled.
STEEGLE PRACTICE
NIS2 (EU Health & Ess.)
Critical sector data is safeguarded by default within your tenant environment.
STEEGLE PRACTICE
DORA (EU Financial Sect.)
Operational resilience and risk controls are maintained within your tenant environment.
STEEGLE PRACTICE
CMMC Level 1
For US Federal Supply Chains
CMMC Level 1 covers 15 basic safeguarding practices under FAR Clause 52.204-21. It flows down contractually through any US DoD prime's supply chain to every supplier involved, regardless of where that supplier is based.
| Category | Details |
|---|---|
|
Assessment type
|
Annual self-assessment
|
|
Basis
|
FAR 52.204-21 · 15 practices |
|
Foreign supplier path
|
NCAGE / SAM.gov, or contractual affirmation to prime |
Limited access — No ongoing data access; setup is temporary and permission-based.
UK registration — Steegle can register in SAM.gov with an NCAGE code.
Contractual assurance — Steegle can provide assurance directly to the prime contractor.
NEN 7510, DORA & NIS2
For Our Netherlands & Belgium Clients
Our healthcare and finance clients operate under strict sector regulations, which extend security expectations to suppliers like us.
| Framework | Details |
|---|---|
|
NEN 7510 basis
|
ISO 27001
+ Dutch healthcare-specific controls
|
|
DORA scope
|
Insurance, financial entities & their ICT suppliers |
|
NIS2 scope
|
Healthcare & other essential sectors
Not our insurance clients
|
Healthcare (NL) — Clients follow NEN 7510 (ISO 27001-based) and, where applicable, NIS2.
Finance (BE/EU) — Clients operate under DORA, which governs ICT third-party risk and takes precedence over NIS2.
Framework alignment — Architecture supports core requirements around access control, incident response, and third-party risk.
Data Sovereignty vs. Data Retrievability
Full Control, Zero Dependency
It's important to understand the distinction between data sovereignty and data retrievability:
Data Retrievability: Focuses on ensuring data can be easily extracted when needed.
Data Sovereignty: Prioritizes keeping your data within your existing Google Workspace environment from the beginning.
Steegle.One emphasizes data sovereignty for added security, control, and ease in exercising the right to be forgotten.
Your Data is Always Yours
While other intranet platforms may describe security and access controls, we believe that having your own data on your own Google Workspace is the ultimate form of security. With Steegle.One, you can be confident that your data is secure without sacrificing ease-of-use or functionality.
Experience the Difference
Try Steegle.One today and experience the difference of a boutique provider with an approach to security that puts your data first. Our platform is designed for organizations of all sizes, and we're committed to providing our clients with a secure, reliable, and user-friendly intranet solution.
Secure Your Digital Workplace
Learn how our unique Google-native security model protects your data. Explore our core features, review real-world client implementations, find answers to compliance questions, or browse our success stories.
Robust Intranet Features
Discover how our features integrate seamlessly into your secure Google Workspace environment without compromising data privacy.
Core Intranet Benefits
See how a low-maintenance intranet empowers your team, reduces IT support tickets, and boosts organizational productivity.
Secure Success Stories
Read how organizations, including healthcare providers, leverage our HIPAA-ready infrastructure to collaborate safely.
View Flexible Pricing Plans
Find a cost-effective, scalable subscription tier tailored to deliver maximum value and ROI for your growing business.
| Feature | Steegle.One | Competitors (e.g., LumApps, MangoApps, Jostle, Happeo) |
|---|---|---|
|
Data Location
|
Client’s Google Workspace | Often on third-party servers like Amazon Web Services (AWS), GCP, or Azure |
|
Service-End Data Migration
|
No Migration Needed | Complex reverse-out/export often required |
|
Data Sovereignty Emphasis
|
High | High |
|
CMMC Level 1 Alignment
|
Minimal control surface, UK supplier-ready | Typically requires securing separate infrastructure |
|
Education Sector
COPPA, FERPA, APPR
|
DPA template, 8 NYCRR Part 121 & NIST CSF mapping available | Varies by vendor |
Key Takeaways: Steegle.One vs Competitors
Conclusion
In a world increasingly focused on data privacy, ownership, and complying with regulations like GDPR, Steegle.One emerges as a compelling choice for businesses. By building upon the robust security of Google Workspace, Steegle.One delivers a unique proposition: ensuring data never leaves your control. This approach fosters trust, simplifies data management, and empowers businesses to take charge of their digital assets.
Frequently Asked Questions
AI People Search & Data Privacy
-
No. All queries and results are processed entirely within your organization's Google Workspace environment. Employee profiles, skills, and experience data never leave your tenant and are not sent to any external AI service.
-
AI People Search leverages Google's existing compliance and security framework. Because all processing happens inside your Workspace domain, data sovereignty is maintained, and regulatory requirements such as GDPR and HIPAA are respected without additional contracts or third-party exposure.
-
No. AI People Search respects existing Google Workspace permissions. Employees only see information they are authorized to access, ensuring sensitive details remain protected and visible only to the right audience.
-
Queries are interpreted and resolved entirely within your Workspace tenant using Gemini AI. No logs, queries, or results are transmitted or stored outside your domain, eliminating the risk of replication in external systems.
-
AI People Search is embedded natively into Google Workspace and works with Vertex AI, inheriting Google's enterprise-grade security protocols, encryption standards, and compliance certifications without introducing new systems or vulnerabilities.
-
No. Steegle.One's AI People Search runs entirely within your existing Google Workspace tenant using your own Gemini environment, with zero third-party data replication and no external API calls, ensuring full compliance with your existing security protocols.
Standards & Compliance
-
Because Steegle.One lives entirely inside Google Workspace, we inherit Google's own independently audited certifications: SOC 2 Type II, ISO 27001, ISO 27017/27018, GDPR compliant processing, and HIPAA via Business Associate Agreement. Our own service practices additionally support FERPA, COPPA, PPRA, IDEA, NYSED, and CMMC Level 1.
-
In the large majority of engagements, no. Clients install our gadgets and applications themselves, and Steegle never touches the data. For clients who choose a full service, white glove migration or build, our team may have temporary, scoped technical access during the engagement, governed by two factor authentication and defined service windows.
-
Yes. Steegle.One holds no standing data of its own and runs inside your own Google Workspace domain, removing most of the infrastructure that CMMC Level 1's basic safeguarding practices under FAR 52.204-21 are designed to protect.
-
Yes. CMMC flows down through the supply chain of any US Department of Defense prime contract, regardless of where the supplier is based. As a UK-registered company, we support US clients and their federal supply chains by aligning with CMMC Level 1's safeguarding practices, and can register in SAM.gov with an NCAGE code where a contract requires direct affirmation.
-
Yes. NEN 7510 is the Dutch information security standard for healthcare, built on ISO 27001 with additional healthcare-specific controls, and it extends to suppliers of software and ICT services, not just care providers themselves. Because Steegle.One holds no standing data and access during implementation is scoped and temporary, our architecture is designed to support NEN 7510's core requirements around access control and secure data exchange.
-
Yes. The Digital Operational Resilience Act (DORA) sets ICT risk management requirements for EU insurance and financial entities, and extends obligations to their third party ICT providers through contractual and technical requirements. DORA applies directly to the regulated client, not to us; our role as a supplier is to support the requirements that flow down through the contract.
-
No, this is worth being precise about. DORA is ‘lex specialis’ for the financial sector, meaning it takes precedence over NIS2 for insurance and financial entities’ ICT risk management. NIS2 is separately relevant to our healthcare clients, since healthcare is a covered ‘essential entity’ sector under NIS2, and can extend supply chain security expectations to suppliers like us.
-
Yes. NYSED requires educational agencies to post a completed Parents' Bill of Rights for Data Privacy and Security, along with contractor-specific supplemental information, for every vendor handling PII. We complete and sign this as Exhibit A of our standard education DPA for every relevant engagement.
-
Yes. Teacher and Principal Annual Professional Performance Review (APPR) data, protected under NYSED rules, is treated as its own category in our education Data Privacy Agreements, distinct from general Student PII, with access even more tightly scoped since it’s rarely needed for the services we provide.
-
Yes. We maintain a standard Data Privacy Agreement template covering FERPA, COPPA, PPRA, NYSED, and APPR obligations, including a NIST Cybersecurity Framework mapping, available on request for education sector prospects.
Want to walk through this with your compliance team?
We'll go through every standard above, and share our Data Privacy Agreement template on request.
Schedule A Compliance Walkthrough With Our Steegle Experts
Stephen Hind
Google Workspace Technical Leader
Peter Chadha
Google Workspace Transformation Leader