Security, privacy, and customer data
Review the public security, privacy, data request, and sub-processor boundaries.
- For
- Company admins, evaluators, and security reviewers
- Owner
- Security and compliance
- Outcome
- Complete a security and privacy review using current public evidence and approved answers.
- Last verified
- 2026-08-30
- Next review
- 2026-11-28
- Status
- supported
Customer journey
Evaluate and secure
- Estimated time
- 12 min
- Permissions and roles
- Evaluator · Company admin · Security reviewer
Open the completion checklistSteps, proof, and recoveryClose checklist
Prerequisites
- The customer security questionnaire
- The intended data and integration scope
- A named security and support owner
Permissions in practice
- Security reviewer: review the public security and privacy record.
- Company admin: confirm workspace controls and export ownership.
Steps
- Read the public privacy, security, subprocessors, service, and support boundaries.
- List the data types, users, providers, retention, access, and export requirements.
- Map each control to Sakhaa, the customer, or the external provider that owns it.
- Record evidence questions and approved follow-up items without sending secrets or customer data.
Success proof
- The reviewer has a written control owner for each requirement.
- The customer knows which claims are documentation proof and which need tenant or provider proof.
Common failures
- A security answer depends on a tenant setting or provider approval.
- A support request includes a secret or unnecessary customer record.
Recovery
- Use the public policy page for product boundaries and the in-app support path for workspace-specific evidence.
- Redact secrets and customer details before sharing a safe error code or timestamp.
Rollback
- Pause the rollout until an unresolved security control has an approved owner.
- Do not enable a provider or import until the data scope is accepted.
Next task
Confirm roles and access for the customer workspace.
Use the linked public documents for current legal and security statements. This guide explains how to prepare a customer review without turning an internal target into a public promise.
Review the public record
- Read the security overview for current product safeguards and reporting guidance.
- Read the privacy policy and data processing agreement for processing responsibilities.
- Review the current sub-processor list for the planned product scope.
- Use the data request path for approved access, correction, deletion, or related requests.
Confirm the customer scope
- List the customer data types, users, regions, providers, exports, and retention rules.
- Confirm the smallest roles and connections required for that scope.
- Record each question, public source, answer owner, and approval date.
- Escalate unanswered legal or security commitments to the approved owner.
Keep evidence safe
- Do not put credentials, customer records, or confidential questionnaires in public documentation feedback.
- Do not use production customer data in screenshots, tests, or support examples.
- Keep signed agreements and customer-specific answers in their approved private systems.