Last updated: 8 August 2026
Last updated: 8 August 2026
EbaSaiyo connects to business communications and may process sensitive operational data. Trust is therefore a core product requirement.
This page is designed to state what EbaSaiyo actually does without claiming certifications or controls that have not been independently verified.
EbaSaiyo's application design includes:
EbaSaiyo uses a specialized identity provider for user authentication and session management. Workspace and application authorization are enforced separately so authentication alone does not grant access to another organization's data.
Customers are responsible for protecting their own identity-provider accounts and devices. MFA availability may depend on identity-provider and plan configuration.
Customer data is associated with an Organization/Workspace. Application endpoints must verify the authenticated user's membership before accessing tenant data.
AI Employees, email connections, messages, drafts, and settings are intended to be scoped through the Customer's organization so identifiers alone do not authorize access.
EbaSaiyo supports OAuth-based integrations with supported email providers rather than asking customers to provide their normal mailbox password.
For Microsoft Graph, EbaSaiyo's intended architecture uses delegated permissions, so the Service acts on behalf of the authorized user within permissions granted through Microsoft.
For Google Workspace/Gmail, EbaSaiyo is designed to request only permissions needed for customer-facing email features and to comply with Google's applicable API user-data requirements.
Sensitive OAuth credentials are stored server-side. The current application architecture encrypts email-provider tokens at rest using authenticated encryption rather than storing them as plaintext application fields.
Production key management, access permissions, and rotation procedures should be maintained as part of EbaSaiyo's internal security program.
AI Employees may operate in different autonomy modes. Safety controls include, depending on configuration:
A confidence indicator is not a guarantee that AI output is correct.
EbaSaiyo may send relevant Customer Content to an API-based AI provider to provide enabled features.
Where OpenAI's API platform is used, OpenAI states that business/API inputs and outputs are not used to train its models by default unless the customer explicitly opts in to sharing. Provider-specific abuse-monitoring and retention controls may still apply.
EbaSaiyo does not intentionally opt Customer Content into general model training without appropriate customer agreement and disclosure.
EbaSaiyo is designed to use:
Database-level encryption, infrastructure encryption, and backup encryption may also be provided by EbaSaiyo's cloud vendors under their respective security programs. Exact production controls should be verified against current vendor documentation and contracts.
EbaSaiyo uses third-party cloud infrastructure and SaaS providers for hosting, database, authentication, AI processing, and other functions. A current list appears in the Subprocessors disclosure.
EbaSaiyo evaluates access and architecture to minimize unnecessary exposure of Customer Content.
EbaSaiyo records application and operational events needed for troubleshooting and security. AI decision logs may include the AI Employee, selected action, autonomy context, confidence information, triggered rules, and human overrides.
EbaSaiyo seeks to avoid unnecessary logging of secrets such as access and refresh tokens.
EbaSaiyo maintains or will maintain a documented incident-response process for triage, containment, remediation, recovery, and customer notification.
Confirmed Personal Data Breaches affecting Customer Personal Data will be communicated without undue delay as required by applicable law and the Data Processing Addendum.
Security issues can be reported to: contact@ebasaiyo.com.
Customer Content is retained only as needed to operate the Service, meet contractual commitments, support security, and satisfy legal obligations.
Upon account termination or valid deletion instruction, data is deleted according to EbaSaiyo's deletion workflow and backup lifecycle, subject to legal retention requirements.
Exact production retention periods should be published once the launch configuration is finalized.
EbaSaiyo is designed for business customers that may operate in the European Economic Area. Where EbaSaiyo processes Customer Personal Data on behalf of a customer, the Data Processing Addendum is intended to address GDPR Article 28 obligations.
International transfers are handled using legally recognized mechanisms where required, such as adequacy decisions or Standard Contractual Clauses.
The EU Artificial Intelligence Act applies in substantial part from 2 August 2026. EbaSaiyo treats AI transparency and human control as product requirements.
Customers using AI Employees to interact directly with individuals are responsible for determining whether an AI disclosure is required for their use case and for ensuring required transparency is provided.
Google classifies some Gmail API permissions as sensitive or restricted. Apps that store or transmit restricted-scope data may be subject to OAuth verification and security assessment requirements.
EbaSaiyo must complete all verification and assessment steps applicable to the final production scopes before broad public launch of the relevant Google integration.
Current public claim: EbaSaiyo does not claim SOC 2, ISO 27001, PCI DSS, HIPAA, or similar certification unless a current certification is expressly published here.
Using infrastructure vendors that hold certifications does not itself make EbaSaiyo certified.
Researchers who believe they have found a vulnerability should contact contact@ebasaiyo.com with sufficient detail for reproduction. Do not access, alter, retain, or disclose data belonging to other customers beyond the minimum necessary to demonstrate a vulnerability.
See Subprocessors.md for providers used to operate EbaSaiyo and how they relate to Customer data.