Skip to main content

Our Security & Compliance

🔐AES-256 + TLS/SSL Encryption
< 24 h Breach Notification
5 Business Days for Data Requests
🔍Annual Penetration Tests

GDPR Compliance

Data Processing Agreement (Art. 28)

A GDPR-compliant DPA under Article 28 is available for every customer and strongly recommended before processing personal data.

Documented TOMs, Reviewed Quarterly

Our technical and organisational measures are fully documented and reviewed at least once per quarter.

Data Protection Impact Assessment (Art. 35)

A comprehensive DPIA has been conducted and is kept up to date in line with Article 35 GDPR.

Regular Internal Audits

Ongoing internal security reviews ensure our controls remain effective and up to date.

Transparent Communication

We document and communicate the nature, purpose, and scope of all processing activities clearly.


EU AI Act

Risk Classification
Limited Risk — Transparency obligations apply

Under the EU AI Act, Sally AI is classified as a Limited Risk system. This means AI systems that interact with people must clearly disclose that they are AI. Sally AI meets all applicable transparency requirements.

Sally AI does not fall into any prohibited or high-risk use case categories — there is no biometric identification, no social scoring, and no use in employment or credit decision-making.

Meeting participants are notified automatically via a transparency notice posted in the meeting chat before recording begins.
Organizers can notify participants via email before the meeting about Sally's use — participants must actively consent before any recording begins.
No high-risk use cases. EU AI Act declaration available for download on request.

Technical Measures (TOMs)

Encryption & Access
  • TLS/SSL for all data in transit
  • AES-256 for all data at rest
  • MFA on all internal systems
  • Role-based access control (RBAC) — least privilege
  • Tenant-level data separation
Infrastructure & Monitoring
  • Audit logging of all access and changes
  • Continuous monitoring + automated anomaly alerts
  • DDoS protection + rate limiting
  • Microsoft Sentinel / Azure Security Center
  • Geo-redundant backups
Data Masking (AI)
  • Personal data masked BEFORE any LLM processing
  • Names & emails replaced with anonymised placeholders
  • Original data restored in our own secure infrastructure
  • Azure OpenAI deployed in EU region — no data leaves EU
  • Microsoft: submitted data NOT used to train OpenAI models
Employee & Organisation
  • Confidentiality commitments for all staff
  • Recurring privacy & security training
  • Need-to-know + dual-control principles
  • Regular security awareness programmes

SOC 2 & ISO 27001

SOC 2July 2026

Actively working toward SOC 2 Type II certification. Controls are reviewed and documented quarterly. The report will be available on request once certification is complete.

ISO 27001June 2026

Hosted in ISO 27001-certified EU data centers (Microsoft Azure). Security management is aligned with ISO 27001 principles including regular reviews, risk analysis, and control assessments.


Roles & Responsibilities

Sally AI
Data Processor
  • Processes data only on documented customer instructions
  • No use of data for own purposes
  • No AI training on customer data — ever
  • Supports data subject requests within 5 business days
Customer
Data Controller
  • Defines the purposes and means of processing
  • Selects the lawful basis for processing
  • Informs end users about data processing
  • Responds to data subject rights requests

Incident Response

1
Detection & Alerting

Automated detection via Microsoft Sentinel and Azure Security Center continuously monitors for anomalies and security events.

2
Triage & Containment

Immediate response actions are taken to limit impact and stabilise affected systems.

3
Analysis & Remediation

Root-cause analysis is conducted, the issue is fixed, and affected services and data are recovered.

4
Customer Notification

Customers are notified without undue delay — no later than 24 hours after we become aware of the incident, as required by the DPA.

5
Documentation & Closure

A full incident report is produced including a complete impact assessment and lessons-learned documentation.

⚠ Note:

Notifying supervisory authorities (GDPR Art. 33 — 72-hour deadline) is the responsibility of the data controller (customer). We support assessment and documentation throughout the process.


Penetration Testing

  • Annual external penetration tests conducted by independent security firms
  • Scope covers: application layer, infrastructure, and access controls
  • Full reports available to customers on request
  • 📧Contact: privacy@sally.io

Full technical details are in Annex 1 (TOMs) of the DPA — download here.