Sally AI is built for organizations with strict security and compliance requirements. Our technical and organizational measures (TOMs), independent ISO certifications, and adherence to regulations like the GDPR and EU AI Act underpin our entire platform.
How we keep your data safeEverything about security & compliance
Our GDPR foundations, TOMs, and role split (controller/processor).
How Sally AI is classified as Limited Risk under Regulation (EU) 2024/1689, transparency obligations, and the AI compliance statement.
Our independent ISO 9001:2015, ISO 14001:2015, and ISO 27001:2022 certifications, with verifiable certificate from DICIS.
Our 24-hour breach notification process and the annual external penetration tests we conduct.
AES-256 at rest, TLS 1.3 in transit, keys held only by Aliru with annual and event-driven rotation, no infrastructure-provider access.
Daily full backups, log-based point-in-time recovery, database cluster with automatic failover, and annually tested restore procedures, all in Germany.
Azure DevOps, weekly Saturday rollouts, four-eyes approval, mandatory manual and automated tests, and rollback capability for every production change.
Four priority classes with binding time-to-remediation targets from "immediately" (critical) to three days (low), with compensating controls when a window cannot be met.
Privileged access on VPN + MFA only, from managed and compliant devices via Intune, Defender and Conditional Access, with break-glass accounts in Entra ID.
Need our compliance documents?
Find DPA, TOMs, RoPA, DPIA, ISO certificate, and the AI compliance statement in our Download Center.