Skip to main content

Our security & compliance

This page is your single source of truth for security and compliance at Sally AI. It documents our technical and organisational measures (TOMs), GDPR conformity, and our role split as a Data Processor. Detailed topics such as the EU AI Act, ISO certifications, and our incident-response process have their own subpages, linked at the bottom. The full underlying documents (TOMs, RoPA, DPIA, AI Act statement) are available in the Download Center.

🔐AES-256 + TLS 1.3 Encryption
< 24 h Breach Notification
5 Business Days for Data Requests
🔍Annual Penetration Tests

GDPR compliance

Data Processing Agreement (Art. 28)

A GDPR-compliant DPA under Article 28 is available for every customer and strongly recommended before processing personal data.

Documented TOMs, Reviewed Quarterly

Our technical and organisational measures are fully documented and reviewed at least once per quarter.

Data Protection Impact Assessment (Art. 35)

A comprehensive DPIA has been conducted and is kept up to date in line with Article 35 GDPR.

Regular Internal Audits

Ongoing internal security reviews ensure our controls remain effective and up to date.

Transparent Communication

We document and communicate the nature, purpose, and scope of all processing activities clearly.


Technical measures (TOMs)

Encryption & Access
  • TLS 1.3 for all data in transit
  • AES-256 for all data at rest
  • MFA on all internal systems
  • Role-based access control (RBAC), least privilege
  • Tenant-level data separation
Infrastructure & Monitoring
  • Audit logging of all access and changes
  • Continuous monitoring + automated anomaly alerts
  • DDoS protection + rate limiting
  • Microsoft Sentinel / Azure Security Center
  • Geo-redundant backups
AI processing
  • Sally's own LLM, operated end-to-end in Germany
  • No external AI providers involved, data never leaves our systems
  • Same encryption, RBAC and audit logging as the rest of the platform
  • Bring Your Own LLM configuration available
  • No customer data ever used to train AI models
Employee & Organisation
  • Confidentiality commitments for all staff
  • Recurring privacy & security training
  • Need-to-know + dual-control principles
  • Regular security awareness programmes

Roles & responsibilities

Sally AI
Data Processor
  • Processes data only on documented customer instructions
  • No use of data for own purposes
  • No AI training on customer data, ever
  • Supports data subject requests within 5 business days
Customer
Data Controller
  • Defines the purposes and means of processing
  • Selects the lawful basis for processing
  • Informs end users about data processing
  • Responds to data subject rights requests

More on security & compliance


Full technical details are in Annex 1 (TOMs) of the DPA (download).