Last updated: 21 August 2026
Last updated: 21 August 2026
EbaSaiyo connects to business communications and may process sensitive operational data. Trust is therefore a core product requirement.
This page is designed to state what EbaSaiyo actually does without claiming certifications or controls that have not been independently verified.
EbaSaiyo's application design includes:
EbaSaiyo uses a specialized identity provider for user authentication and session management. Workspace and application authorization are enforced separately so authentication alone does not grant access to another organization's data.
Customers are responsible for protecting their own identity-provider accounts and devices. MFA availability may depend on identity-provider and plan configuration.
Customer data is associated with an Organization/Workspace. Application endpoints must verify the authenticated user's membership before accessing tenant data.
AI Employees, email connections, messages, drafts, and settings are intended to be scoped through the Customer's organization so identifiers alone do not authorize access.
EbaSaiyo supports OAuth-based integrations with supported email providers rather than asking customers to provide their normal mailbox password.
For Microsoft Graph, EbaSaiyo's intended architecture uses delegated permissions, so the Service acts on behalf of the authorized user within permissions granted through Microsoft.
For Google Workspace/Gmail, EbaSaiyo is designed to request only permissions needed for customer-facing email features and to comply with the Google API Services User Data Policy, including Limited Use. Google user data is used only to provide or improve user-facing features for the authorizing customer/user and is not used to train, improve, or develop generalized or shared AI models or foundation models.
Sensitive OAuth credentials are stored server-side. The current application architecture encrypts email-provider tokens at rest using authenticated encryption rather than storing them as plaintext application fields.
On mailbox disconnect (or related AI Employee / workspace deletion), EbaSaiyo performs a best-effort remote revoke and wipes encrypted tokens from active systems. Residual copies may remain temporarily in protected backups until backup expiry.
EbaSaiyo maintains production key management, access permissions, and rotation procedures as part of its internal security program.
AI Employees may operate in different autonomy modes. Safety controls include, depending on configuration:
A confidence indicator is not a guarantee that AI output is correct.
EbaSaiyo may send relevant Customer Content to an API-based AI provider to provide enabled features.
Where OpenAI's API platform is used, OpenAI states that business/API inputs and outputs are not used to train its models by default unless the customer explicitly opts in to sharing. Provider-specific abuse-monitoring and retention controls may still apply.
EbaSaiyo does not intentionally opt Customer Content into general model training without appropriate customer agreement and disclosure.
EbaSaiyo is designed to use:
Database-level encryption, infrastructure encryption, and backup encryption may also be provided by EbaSaiyo's cloud vendors under their respective security programs.
EbaSaiyo uses third-party cloud infrastructure and SaaS providers for hosting, database, authentication, AI processing, and other functions. A current list appears in the Subprocessors disclosure.
EbaSaiyo evaluates access and architecture to minimize unnecessary exposure of Customer Content.
EbaSaiyo records application and operational events needed for troubleshooting and security. AI decision logs may include the AI Employee, selected action, autonomy context, confidence information, triggered rules, and human overrides.
EbaSaiyo seeks to avoid unnecessary logging of secrets such as access and refresh tokens.
EbaSaiyo maintains a documented incident-response process for triage, containment, remediation, recovery, and customer notification.
Confirmed Personal Data Breaches affecting Customer Personal Data will be communicated without undue delay as required by applicable law and the Data Processing Addendum.
Security issues can be reported to: contact@ebasaiyo.com.
Customer Content is retained only as needed to operate the Service, meet contractual commitments, support security, and satisfy legal obligations.
Deletion follows EbaSaiyo's product deletion workflow:
More specific retention periods may be published in product documentation or provided on request where required.
EbaSaiyo is designed for business customers that may operate in the European Economic Area. Where EbaSaiyo processes Customer Personal Data on behalf of a customer, the Data Processing Addendum addresses GDPR Article 28 obligations.
International transfers are handled using legally recognized mechanisms where required, such as adequacy decisions or Standard Contractual Clauses.
The EU Artificial Intelligence Act applies in substantial part from 2 August 2026. EbaSaiyo treats AI transparency and human control as product requirements.
Customers using AI Employees to interact directly with individuals are responsible for determining whether an AI disclosure is required for their use case and for ensuring required transparency is provided.
Google classifies some Gmail API permissions as sensitive or restricted. Apps that store or transmit restricted-scope data may be subject to OAuth verification and security assessment requirements.
EbaSaiyo's use of Google user data complies with the Google API Services User Data Policy, including Limited Use: data is used only to provide or improve customer-facing features for the authorizing customer/user and is not used to train, improve, or develop generalized or shared AI models or foundation models.
EbaSaiyo must complete all verification and assessment steps applicable to the final production scopes before broad public launch of the relevant Google integration.
Current public claim: EbaSaiyo does not claim SOC 2, ISO 27001, PCI DSS, HIPAA, or similar certification unless a current certification is expressly published here.
Using infrastructure vendors that hold certifications does not itself make EbaSaiyo certified.
Researchers who believe they have found a vulnerability should contact contact@ebasaiyo.com with sufficient detail for reproduction. Do not access, alter, retain, or disclose data belonging to other customers beyond the minimum necessary to demonstrate a vulnerability.
See the Subprocessors page for providers used to operate EbaSaiyo and how they relate to Customer data.