Skip to main content

Our Security & Compliance

This page is your single source of truth for security and compliance at Sally AI. It documents our technical and organisational measures (TOMs), GDPR conformity, and our role split as a Data Processor. Detailed topics such as the EU AI Act, ISO certifications, and our incident-response process have their own subpages, linked at the bottom. The full underlying documents (TOMs, RoPA, DPIA, AI Act statement) are available in the Download Center.

🔐AES-256 + TLS/SSL Encryption
< 24 h Breach Notification
5 Business Days for Data Requests
🔍Annual Penetration Tests

GDPR Compliance

Data Processing Agreement (Art. 28)

A GDPR-compliant DPA under Article 28 is available for every customer and strongly recommended before processing personal data.

Documented TOMs, Reviewed Quarterly

Our technical and organisational measures are fully documented and reviewed at least once per quarter.

Data Protection Impact Assessment (Art. 35)

A comprehensive DPIA has been conducted and is kept up to date in line with Article 35 GDPR.

Regular Internal Audits

Ongoing internal security reviews ensure our controls remain effective and up to date.

Transparent Communication

We document and communicate the nature, purpose, and scope of all processing activities clearly.


Technical Measures (TOMs)

Encryption & Access
  • TLS/SSL for all data in transit
  • AES-256 for all data at rest
  • MFA on all internal systems
  • Role-based access control (RBAC), least privilege
  • Tenant-level data separation
Infrastructure & Monitoring
  • Audit logging of all access and changes
  • Continuous monitoring + automated anomaly alerts
  • DDoS protection + rate limiting
  • Microsoft Sentinel / Azure Security Center
  • Geo-redundant backups
Data Masking (AI)
  • Personal data masked BEFORE any LLM processing
  • Names & emails replaced with anonymised placeholders
  • Original data restored in our own secure infrastructure
  • Azure OpenAI deployed in EU region, so no data leaves EU
  • Microsoft: submitted data NOT used to train OpenAI models
Employee & Organisation
  • Confidentiality commitments for all staff
  • Recurring privacy & security training
  • Need-to-know + dual-control principles
  • Regular security awareness programmes

Roles & Responsibilities

Sally AI
Data Processor
  • Processes data only on documented customer instructions
  • No use of data for own purposes
  • No AI training on customer data, ever
  • Supports data subject requests within 5 business days
Customer
Data Controller
  • Defines the purposes and means of processing
  • Selects the lawful basis for processing
  • Informs end users about data processing
  • Responds to data subject rights requests

More on Security & Compliance


Full technical details are in Annex 1 (TOMs) of the DPA. Download here.