Salt AI logo
Agents Orchestration Frameworks · Workflow Automation

Salt AI

Salt AI is an AI orchestration platform for regulated enterprises. Its Salt OS product builds governed, auditable, model-agnostic workflows that run inside your own private cloud, on-premises or air-gapped infrastructure, serving life sciences, finance, energy and government teams.

Active Contact Sales API available 18+ Verified by Guidaio
Overview

What is Salt AI?

Salt AI is the commercial brand of Salt OS, Inc., a Los Angeles company founded in 2023 by Aber Whitcomb, previously co-founder and CTO of MySpace and Jam City, and Jim Benedetto, its CTO. The product, Salt OS, presents itself as a secure operating system for enterprise intelligence: an orchestration layer that unifies models, data, governance and context so AI workflows run where the data already lives instead of being shipped to somebody else’s API.

Four architectural pillars carry that promise. Context-aware orchestration captures prompts, parameters, model behavior and user context on every execution. Private deployment puts the platform in an air-gapped enclave, on the customer’s own hardware or inside its cloud VPC, with no public egress by default. A complete audit trail logs each input, prompt, parameter, output and error, with lineage tracking. A model-agnostic runtime lets teams move between frontier and open-source models without rebuilding anything.

Three deployment options are documented: Private VPC on AWS, Azure, OCI or GCP; On-Premises, containerized, air-gap compatible and able to plug into existing SSO; and Air-Gapped, aimed at IL4/IL5 environments, SAP/SCI enclaves, a FedRAMP High path, FAR/DFARS and agency ATO work. The product journey runs Build, Deploy, Optimize, Scale, while Salt Matrix catalogs connectors, models and sector solutions. Public documentation at docs.salt.ai covers pipelines, Ask Salt for natural-language queries over connected data, custom agents, an MCP server and connectors; a finished pipeline can be published as a REST API, a web form or an agent tool.

Four regulated verticals are served: life sciences, financial services, energy and utilities, and the public sector. Named references include the Ellison Medical Institute, a partner since the summer of 2024, Dr. Dino Di Carlo’s laboratory at UCLA and Hiteks, with a Cloudera partnership announced on 12 March 2026. The team page claims an 85% cut in implementation time and more than twenty years of collaboration among the founders. Certifications include SOC 2 Type I and Type II audited by Sensiba LLP, HIPAA, ISO 27001 cited in the documentation, and 21 CFR Part 11 and GxP coverage for life sciences. No price is published anywhere on the site.

What it does

  • Build a multi-model pipeline by drag-and-drop on a blank canvas, or generate one from a plain-language instruction in chat
  • Deploy the whole stack inside a private VPC, on-premises or an air-gapped enclave, in a matter of days
  • Swap one model for another, across generations and architectures, without rewriting the pipeline
  • Publish a pipeline as a REST API, a web form or a tool an agent can call
  • Run batches of thousands of executions with real-time monitoring, then replay and debug failures from full traces
  • Query connected data in natural language through Ask Salt, and build custom agents with pipelines attached as tools
  • Export pipelines to Python or Docker containers, and connect Salt to Claude Code through its MCP server
Audience

When to use Salt AI / When not to

A quick filter to help you decide if Salt AI is the right fit.

When to use Salt AI

  • Life sciences teams in discovery, clinical development or medical affairs that must keep molecule and patient data under HIPAA, GxP and 21 CFR Part 11 control
  • Banks, asset managers and capital markets desks whose AI use has to survive SEC, FINRA, OCC, MiFID II and Dodd-Frank scrutiny
  • Federal agencies, defense and intelligence programs that need IL4/IL5, SAP/SCI enclaves, a FedRAMP High path or agency ATO support
  • Energy and utility operators answerable to PHMSA, EPA and FERC who need traceable, reproducible analysis of field, pipeline and grid data
  • Mixed teams of scientists and engineers who want a drag-and-drop canvas without giving up full-code depth or the ability to export pipelines to Python and Docker

When not to use Salt AI

  • Individuals and small teams hoping to sign up on their own: there is no public price list and no self-serve registration, only a sales form
  • Anyone based outside the United States, since the terms of service restrict use to residents of the US and its territories
  • European organizations that need a GDPR posture, as no Article 27 representative, no named DPO and no data processing agreement are published
  • Companies without infrastructure or platform engineers, because a private VPC, on-premises or air-gapped rollout has to be stood up on the customer side
  • Mobile-first users, as neither an iOS nor an Android application exists
Get started

How to use Salt AI

A typical end-to-end flow, from setup to results.

  1. Start on the contact page and send the Book Demo or Contact Us form with your name, work email, company and a reason such as Product demo or Pricing
  2. Expect an answer within one business day, as there is no self-serve sign-up to bypass the sales conversation
  3. Agree on a deployment option: private VPC on AWS, Azure, OCI or GCP, on-premises, or fully air-gapped
  4. Stand the environment up, which the site says takes days rather than months, using containerized builds and your existing SSO
  5. Register an API key for each connector you need; credentials are scoped to the account and never surface in pipeline definitions or logs
  6. Build a first pipeline by dragging nodes onto a blank canvas, or describe the workflow in chat and let Salt generate it
  7. Invite colleagues to edit the same workflow with you in real time
  8. Optimize: tune, test and swap models without rewriting the pipeline, and add custom connectors for proprietary data sources
  9. Publish the pipeline as a REST API, a web form or an agent tool, and query connected data through Ask Salt
  10. Scale to batch runs across thousands of executions, watch them live, debug from full traces, and wire Salt into Claude Code through the MCP server if you work from a coding agent
Quick read

Pros & Cons

Pros

  • Data stays in the customer environment: private VPC, on-premises or air-gapped, with no public egress configured by default
  • SOC 2 Type I and Type II certification by a named auditor, Sensiba LLP, with the examination window and report date published rather than merely claimed
  • Regulatory coverage documented vertical by vertical: HIPAA, GxP, 21 CFR Part 11, SEC, FINRA, OCC, MiFID II, Dodd-Frank, PHMSA, EPA, FERC, IL4/IL5, FedRAMP High, FAR/DFARS and FOIA/OIG
  • Genuine agnosticism on three axes at once: model, cloud and vendor
  • No lock-in by design, since pipelines export to Python or Docker containers
  • Two audiences served by one product: a visual canvas for non-technical users, full-code capability for engineers
  • Named customer references and attributable quotes, from the Ellison Medical Institute to UCLA and Hiteks, backed by $13 million raised from named investors

Cons

  • No public pricing whatsoever: no pricing page, no range, no entry tier, and no self-serve registration — every route runs through a sales form
  • Use is contractually limited to people aged 18 or over residing in the United States or its territories
  • The GDPR is absent from the entire site: not one mention, no Article 27 representative, no named DPO and no published DPA, only a HIPAA BAA
  • The terms let the publisher use customer Workflows to train and improve its models, with no documented opt-out
  • No formal subprocessor list is published, and no data hosting country is named anywhere
  • A single generic public address, info@salt.ai, with no dedicated support mailbox, and no mobile application of any kind
  • Consumer-era leftovers still sit in the terms — a Community Workflows marketplace, PayPal payments, and two spellings of the legal name, “Salt OS, Corp” and “Salt OS, Inc” — while the two interactive walkthroughs linked from the energy page returned 503 on 24 August 2026
Pricing

Pricing & Plans

Salt AI publishes no prices. The site carries no pricing page, no indicative range and no named entry tier, and no free plan is advertised, so no lowest price point can be stated; the contact form merely offers Pricing as a reason for getting in touch. Section 4 of the terms of service does describe purchases of Offerings and a Community Workflows marketplace carrying service fees, paid in US dollars by credit card, debit card or PayPal, together with a policy of no refunds except where applicable law requires one. The HIPAA business associate agreement is presented as an Enterprise-level provision. A press release of 17 December 2024 mentioned a free trial at sign-up, but the current site exposes no self-serve registration at all.

No priced plan is published
  • what the site calls options are deployment configurations
  • not commercial tiers
  • and none of them carries a figure
Option 2, On-Premises
  • the customer’s own hardware and network
  • zero external connectivity
  • HIPAA
  • GxP and 21 CFR Part 11 coverage
  • custom retention policies and integration with existing SSO
Option 3, Air-Gapped
  • IL4/IL5 ready
  • compatible with SAP/SCI enclaves
  • a FedRAMP High path
  • FAR/DFARS compliance and support through an agency ATO
Plan 5
  • The HIPAA business associate agreement is labeled Enterprise on the trust page
  • the only place a tier name appears anywhere on the site
Special offers — No promotion, discount, launch offer or preferential rate is published anywhere on the site · The only free items advertised are an interactive product demo requiring neither sign-up nor a sales call, and a general SOC 3 report that can be shared freely · No student, non-profit, startup, referral or affiliate program is mentioned
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Salt AI handles your data.

GDPR overview

There is no GDPR implementation to report. Nowhere on the site — not in the privacy notice, not in the terms — do the words “GDPR” or “General Data Protection” appear at all. The privacy notice of 8 September 2025 goes the other way and scopes the Services to United States users alone, disclaiming any intention to serve people located elsewhere, while the terms of 28 May 2026 limit use to residents of the US and its territories. No Article 27 representative is designated, no data protection officer is named, and the only privacy contact published is the generic address info@salt.ai. The single set of data subject rights addressed is Californian: a registered minor under 18 living in California may request removal of content they posted. Governing law is California, with JAMS arbitration and a class action waiver.

Who owns the data?

The terms label user material “Your Content” and leave the Services themselves, software and branding included, with the publisher and its licensors. Ownership is not the whole story. Clause 7.1 lets Salt use a customer’s Workflow to train or improve its Services, including its AI and machine learning models; the privacy notice of 8 September 2025 adds that inputs may be stored and fed into the company’s own LLM, and that the company or third parties may store, display, reproduce, publish or use outputs, with or without attribution. Feedback becomes the publisher’s exclusive property. The trust page states the reverse for customer deployments — no input, output or intermediate data reaches Salt OS systems — and the site never reconciles the two.

Reuse rights

The privacy notice sets out what is gathered and where it travels. Collected directly: contact details, account identifiers, user-generated content such as messages, photos and recordings, and the inputs and outputs of workflows. Collected automatically: device type, operating system, unique identifier, IP address, approximate location, browser, logs, timestamps, clickstream, marketing email interactions and ad impressions. Analytics vendors such as Google Analytics and social platforms such as Discord supply more. Stated purposes run from account creation, service delivery, communication, security and support through to trend analysis, internal R&D and legal obligations. Recipients include group affiliates, service providers for hosting, security, CRM, marketing, web analytics and payment processing, professional advisers such as auditors, lawyers and accountants, and any acquirer in a sale, merger or bankruptcy; disclosure to authorities and to enforce the terms is reserved. Data may also be deidentified or anonymized and then used freely, and the site is not designed to respond to Do Not Track signals.

Data retention & training

Retention summary
No retention period is given in figures. The privacy notice of 8 September 2025 says only that information is kept for as long as is reasonably necessary for the purposes it describes, and lists those purposes as continuing to provide the Services, resolving disputes, enforcing agreements, preventing harm, promoting safety, security and integrity, and protecting the company’s rights, property and products. Deletion on request appears in two narrow cases only: data belonging to a child under 13 the company identifies, and content posted by a registered California minor. On-premises customers are told they can set their own retention policies, and daily automated backups sit under the incident response and recovery controls. The notice also warns that no measure is impenetrable and that information sent electronically may not be secure in transit.
Trains on customer data
Yes

Hosting summary

The governing principle is that data is hosted by the customer, not by the publisher. Three modes are documented: a private VPC inside the customer’s own AWS, Azure, OCI or GCP account; an on-premises install in the customer’s data center; and an air-gapped deployment with no network path to the public internet. No public egress is configured by default, and on-premises deployments are described as having zero external connectivity. The trust page states that no model input, output or intermediate data is transmitted to Salt OS systems. Responsibility is split three ways: the publisher for platform software security, runtime and orchestration, access control architecture, audit log generation, SDLC and vulnerability management; the cloud provider for physical data center security, network infrastructure, hardware lifecycle and hypervisor isolation; the customer for VPC or on-premises configuration, user provisioning, data classification and access policy enforcement. GCP, AWS and Azure are named under subservice organization oversight, with annual attestation review. Encryption at rest, TLS in transit and daily automated backups are claimed. No hosting country is named, which follows directly from the model: the customer picks the region.

Availability

Where Salt AI works

Country-level availability.

Available in

🇺🇸 United States

Not available in

Every country and territory outside the United States: the terms of service require users to be 18 or over and to reside in the United States or one of its territoriesThe privacy notice draws the same boundary, scoping the Services to United States users alone and disclaiming any intention to serve people located elsewhere; the terms add that anyone reaching the Services from abroad does so on their own initiative and answers for compliance with local law
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Salt AI.

  • The terms and the trust page contradict each other on training: clause 7.1 lets Salt train on your Workflows, while the trust page promises that no input, output or intermediate data ever leaves your environment. The two probably cover different perimeters, the hosted service against a customer deployment, but the site never says so and no opt-out is documented
  • The privacy notice allows the company or third parties to store, display, reproduce, publish or use model outputs, with third parties able to access them, and any feedback you send becomes the company’s exclusive property
  • Dispute resolution is one-sided by construction: mandatory individual arbitration at JAMS, a class action waiver with only a 30-day written opt-out window to info@salt.ai, and a blanket no-refund policy
  • Nothing addresses European law — no Article 27 representative, no named DPO, no DPA and no subprocessor list — while use is contractually reserved to US residents aged 18 or over
  • A complete audit trail can breed false confidence: logging what a model did says nothing about whether the answer was right, and regulated teams still owe a human review of every output that reaches a regulator or a patient
  • Generating workflows from a chat instruction is fast, but a team that stops understanding how its own pipeline is wired will struggle the day an inspector asks it to explain one
  • Small discrepancies worth clearing before signing: two legal names inside the same terms, “Salt OS, Corp” and “Salt OS, Inc”, a privacy notice dated 8 September 2025 sitting beside terms revised 28 May 2026, and two interactive walkthroughs that returned 503 on 24 August 2026
Setup

Setup & Integrations

Technical difficulty

Two very different levels. Getting started is not self-serve: access begins with a sales conversation, and the rollout needs an infrastructure team. Private VPC is presented as the fastest path; on-premises requires the customer’s own hardware, network, storage and SSO integration; air-gapped work targets classified environments and implies agency ATO support. The site claims days rather than months for each. Building workflows is far lighter: a visual canvas for business users, full-code depth for engineers, a first pipeline in minutes according to the documentation, and one API key to register per third-party connector.

Deployment

Web appAPI

Integrations

OpenAI Anthropic Google Gemini Groq Stability AI Ollama Notion Google Drive Slack AlphaFold PubMed OpenFDA Benchling Veeva FactSet Bloomberg GitHub Cloudera CoreWeave Amazon Web Services Google Cloud Microsoft Azure Oracle Cloud Infrastructure DeepSeek
Company

Behind Salt AI

Company name
Salt OS, Inc.
Founded
12/03/2024
Country of origin
🇺🇸 United States
Headquarters
23465 Civic Center Way Building 9, Unit 120, Malibu CA 90265, USA
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact

Fundraising

17 December 2024 — $3 million seed round led by Morpheus Ventures with Struck Capital and Irregular Expressions, announced alongside Aber Whitcomb’s appointment as CEO and quoting Morpheus partner Kristian Blaszczynski
22 September 2025 — $10 million round led by Morpheus Ventures, joined by Struck Capital, Marbruck Investments and CoreWeave, with a quote from CoreWeave co-founder and Chief Strategy Officer Brian Venturo
Stated use of the $10 million: widening the biopharma and healthcare customer base and growing the global AI engineering teams
13 November 2025 — a blog post announced a strengthened leadership bench recruited from biotech and AI in the wake of the $10 million round
Total disclosed on the company’s own blog: $13 million, both announcements being first-party releases published on www.salt.ai/blog

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What exactly is Salt AI?
Salt AI is the commercial brand of Salt OS, Inc. Its product, Salt OS, is a contextual AI orchestration platform for regulated enterprises: it unifies models, data, governance and context in one place and is deployed where the customer’s data already sits.
Where do the workflows actually run?
Inside the customer’s own infrastructure. Three configurations are documented: a private VPC in the customer’s AWS, Azure, OCI or GCP account, an on-premises install on the customer’s hardware, or a fully air-gapped enclave. No public egress is configured by default.
How much does it cost?
No price is published. There is no pricing page, no bracket and no named tier anywhere on the site, so a sales conversation is the only route to a figure; the contact form lists Pricing as one of its reasons for writing in.
Is there a free trial or a free plan?
Neither is exposed today. The site advertises an interactive product demo that requires no sign-up, but there is no self-serve registration and no free tier, and the free trial mentioned in a December 2024 press release no longer appears anywhere.
Which certifications does the platform hold?
SOC 2 Type I and Type II, audited by Sensiba LLP over an examination period running from 5 September to 5 December 2025 with a report dated 9 February 2026. HIPAA is claimed, ISO 27001 is cited in the documentation, and 21 CFR Part 11 and GxP are covered for life sciences.
Which compliance documents can a buyer obtain?
The SOC 2 Type II report under NDA, a freely distributable SOC 3 report, an attestation letter from Sensiba LLP and a HIPAA business associate agreement. All of them are supplied on request through an account representative rather than downloaded from the site.
Is the service GDPR compliant?
The site never mentions the GDPR at all. The privacy notice scopes the Services to United States users alone and disclaims any intention to serve people located elsewhere, and the terms restrict use to people aged 18 or over residing in the US or its territories.
Will my data be used to train Salt’s models?
The terms say the publisher may use your Workflows to train and improve its Services, including its AI and machine learning models. The trust page says the opposite for customer deployments: no input, output or intermediate data reaches Salt OS systems. The site never explains the difference in scope, and no training opt-out is documented.
Is there an API, and what plugs into it?
Yes. Documentation is public at docs.salt.ai, pipelines can be published as REST APIs, and an MCP server is available. Connectors cover OpenAI, Anthropic, Google Gemini, Groq, Stability AI and Ollama for models, Notion, Google Drive and Slack for data and communication, AlphaFold, PubMed, PDB, OpenFDA, Benchling and Veeva in life sciences, and FactSet and Bloomberg in finance.
Is there a mobile app, and how do I reach the company?
There is no iOS or Android application. Contact runs through the form at salt.ai/contact, answered within one business day according to the site, or by email to info@salt.ai. The headquarters is in Los Angeles and the mailing address is in Malibu, California.
Conclusion

Should you pick Salt AI?

Salt AI knows exactly which problem it solves and for whom. Regulated organizations that cannot ship data to a third-party model API get an orchestration layer installed in their own VPC, data center or air-gapped enclave, logging every prompt, parameter and output for the auditor and letting them change model without rebuilding anything. The sovereignty claim is more than marketing: SOC 2 Type I and Type II were audited by a named firm, Sensiba LLP, with examination window and report date published, and the regulatory mapping per vertical — HIPAA and 21 CFR Part 11 in life sciences, SEC, FINRA and MiFID II in finance, PHMSA, EPA and FERC in energy, IL4/IL5 and FedRAMP High in the public sector — is unusually specific for a vendor site.

The blind spots are just as clear. No price appears anywhere, there is no self-serve entry, and the only door is a sales form. The GDPR is never mentioned, use is contractually limited to US residents aged 18 or over, and the terms grant the publisher the right to train on customer Workflows with no documented opt-out — a clause the trust page appears to contradict without the site ever explaining the difference in scope. Consumer-era provisions, a Community Workflows marketplace and PayPal payments among them, still sit in a document last revised in May 2026 and jar with the enterprise positioning.

This is a young company: founded in 2023, $13 million raised over two rounds, named life sciences references including the Ellison Medical Institute. Worth a serious conversation if you are a regulated US enterprise — but before signing, ask in writing which contract governs training on your workflows, whether a data processing agreement exists, and who the subprocessors are.