Compliance
Sazabi's compliance posture — the certified infrastructure and subprocessors behind the platform, privacy regulations, security testing, and availability commitments.
Sazabi runs on certified infrastructure, processes data under recognized privacy regulations, and tests its security continuously. This page summarizes that posture; for contractual specifics, ask for the Data Processing Addendum and subprocessor list.
Certified infrastructure
Production data is hosted on infrastructure that carries SOC 2 and ISO 27001 certifications, and every subprocessor Sazabi relies on carries its own SOC 2 and/or ISO 27001 attestation. A SOC 2 Type II report and HIPAA safeguards are available on select plans — see Pricing for what your plan includes.
Privacy and data protection
Sazabi is a data processor: it processes your data on your instructions and for no other purpose. Sazabi supports GDPR and CCPA, including data subject requests — deletion, correction, and export — and follows data-minimization and purpose-limitation principles. Sazabi will sign a Data Processing Addendum to formalize these responsibilities. See Data handling for how this maps to what happens to your telemetry.
Payment data
Sazabi deliberately scopes cardholder data out of the platform, so PCI-DSS does not apply. Payments are handled by a dedicated payment processor.
Subprocessors
Sazabi uses a defined set of subprocessors to run the platform — infrastructure, storage, AI model providers, and operational tooling. Each carries SOC 2 and/or ISO 27001 attestations. A full, current list, with each subprocessor's purpose and location, is available in the Data Processing Addendum or on request.
Security testing
Sazabi tests its security continuously: dependencies and container images are scanned on every build, code changes go through mandatory review, and automated vulnerability scanning runs against production. On top of that, Sazabi engages independent third parties for annual penetration tests.
Availability
Sazabi publishes uptime commitments that vary by plan. See Pricing for the SLA that applies to your plan.
Report a vulnerability
To report a security issue, contact security@sazabi.ai. Sazabi maintains a direct path for disclosures and responds to reported issues.