EbaSaiyoBack to EbaSaiyo

Security & Trust

Last updated: 21 August 2026

Last updated: 21 August 2026

EbaSaiyo connects to business communications and may process sensitive operational data. Trust is therefore a core product requirement.

This page is designed to state what EbaSaiyo actually does without claiming certifications or controls that have not been independently verified.

Security at a Glance

EbaSaiyo's application design includes:

  • authenticated user access;
  • organization-level tenant isolation;
  • AI Employee resource scoping;
  • delegated OAuth integrations for supported email providers;
  • encrypted storage of sensitive OAuth credentials;
  • server-side secret handling;
  • HTTPS/TLS transport security;
  • AI decision logging for autonomous behavior;
  • human-configurable autonomy and override controls; and
  • business-rule and escalation safeguards for AI communications.

Authentication

EbaSaiyo uses a specialized identity provider for user authentication and session management. Workspace and application authorization are enforced separately so authentication alone does not grant access to another organization's data.

Customers are responsible for protecting their own identity-provider accounts and devices. MFA availability may depend on identity-provider and plan configuration.

Tenant Isolation

Customer data is associated with an Organization/Workspace. Application endpoints must verify the authenticated user's membership before accessing tenant data.

AI Employees, email connections, messages, drafts, and settings are intended to be scoped through the Customer's organization so identifiers alone do not authorize access.

Email Integrations

EbaSaiyo supports OAuth-based integrations with supported email providers rather than asking customers to provide their normal mailbox password.

For Microsoft Graph, EbaSaiyo's intended architecture uses delegated permissions, so the Service acts on behalf of the authorized user within permissions granted through Microsoft.

For Google Workspace/Gmail, EbaSaiyo is designed to request only permissions needed for customer-facing email features and to comply with the Google API Services User Data Policy, including Limited Use. Google user data is used only to provide or improve user-facing features for the authorizing customer/user and is not used to train, improve, or develop generalized or shared AI models or foundation models.

OAuth Credential Protection

Sensitive OAuth credentials are stored server-side. The current application architecture encrypts email-provider tokens at rest using authenticated encryption rather than storing them as plaintext application fields.

On mailbox disconnect (or related AI Employee / workspace deletion), EbaSaiyo performs a best-effort remote revoke and wipes encrypted tokens from active systems. Residual copies may remain temporarily in protected backups until backup expiry.

EbaSaiyo maintains production key management, access permissions, and rotation procedures as part of its internal security program.

AI Safety and Control

AI Employees may operate in different autonomy modes. Safety controls include, depending on configuration:

  • Manual human approval;
  • confidence-based gating;
  • configurable business rules;
  • escalation to a human;
  • no-reply/ignore classification;
  • audit records of AI decisions;
  • human override; and
  • ability to reduce autonomy or disable a connection.

A confidence indicator is not a guarantee that AI output is correct.

Data Used for AI

EbaSaiyo may send relevant Customer Content to an API-based AI provider to provide enabled features.

Where OpenAI's API platform is used, OpenAI states that business/API inputs and outputs are not used to train its models by default unless the customer explicitly opts in to sharing. Provider-specific abuse-monitoring and retention controls may still apply.

EbaSaiyo does not intentionally opt Customer Content into general model training without appropriate customer agreement and disclosure.

Encryption

EbaSaiyo is designed to use:

  • TLS/HTTPS for data in transit; and
  • authenticated encryption for sensitive stored integration credentials.

Database-level encryption, infrastructure encryption, and backup encryption may also be provided by EbaSaiyo's cloud vendors under their respective security programs.

Infrastructure

EbaSaiyo uses third-party cloud infrastructure and SaaS providers for hosting, database, authentication, AI processing, and other functions. A current list appears in the Subprocessors disclosure.

EbaSaiyo evaluates access and architecture to minimize unnecessary exposure of Customer Content.

Logging and Auditability

EbaSaiyo records application and operational events needed for troubleshooting and security. AI decision logs may include the AI Employee, selected action, autonomy context, confidence information, triggered rules, and human overrides.

EbaSaiyo seeks to avoid unnecessary logging of secrets such as access and refresh tokens.

Incident Response

EbaSaiyo maintains a documented incident-response process for triage, containment, remediation, recovery, and customer notification.

Confirmed Personal Data Breaches affecting Customer Personal Data will be communicated without undue delay as required by applicable law and the Data Processing Addendum.

Security issues can be reported to: contact@ebasaiyo.com.

Data Retention and Deletion

Customer Content is retained only as needed to operate the Service, meet contractual commitments, support security, and satisfy legal obligations.

Deletion follows EbaSaiyo's product deletion workflow:

  • Mailbox disconnect: best-effort remote revoke and wipe of encrypted OAuth tokens; deletion of that connection's synced messages, threads, and related AI reply artifacts from active systems; further processing for that connection stops. Knowledge, other connections, business settings, and the workspace are not deleted by a single-mailbox disconnect.
  • AI Employee deletion: purges that employee's connections (with the disconnect wipe), knowledge files for that employee, learning/memory scoped to the employee, and related decision records from active systems. Anonymized usage aggregates (no email bodies) and minimal consent/audit metadata may be retained.
  • Workspace / account deletion: authorized owners can delete a workspace; account holders can delete their account. Operational Customer Content is purged from active systems according to the deletion workflow. Removing a member does not by itself delete the workspace; workspace purge applies when the workspace is deleted (including when account deletion removes the last remaining member).
  • Billing / invoices: retained as required by applicable tax and accounting law, even after workspace deletion, with an anonymized workspace record where needed for invoice linkage.
  • Security logs: retained for a limited period for incident detection and investigation; they are not email bodies or ordinary correspondence.
  • AI usage aggregates: may be retained for a limited period for cost analytics and abuse investigation without prompt or email bodies.
  • Backups: deleted data may remain temporarily in protected provider backups until normal backup expiry and is not restored for ordinary business use except disaster recovery, security investigation, or legal necessity.

More specific retention periods may be published in product documentation or provided on request where required.

Privacy and GDPR

EbaSaiyo is designed for business customers that may operate in the European Economic Area. Where EbaSaiyo processes Customer Personal Data on behalf of a customer, the Data Processing Addendum addresses GDPR Article 28 obligations.

International transfers are handled using legally recognized mechanisms where required, such as adequacy decisions or Standard Contractual Clauses.

EU AI Act

The EU Artificial Intelligence Act applies in substantial part from 2 August 2026. EbaSaiyo treats AI transparency and human control as product requirements.

Customers using AI Employees to interact directly with individuals are responsible for determining whether an AI disclosure is required for their use case and for ensuring required transparency is provided.

Google API Compliance

Google classifies some Gmail API permissions as sensitive or restricted. Apps that store or transmit restricted-scope data may be subject to OAuth verification and security assessment requirements.

EbaSaiyo's use of Google user data complies with the Google API Services User Data Policy, including Limited Use: data is used only to provide or improve customer-facing features for the authorizing customer/user and is not used to train, improve, or develop generalized or shared AI models or foundation models.

EbaSaiyo must complete all verification and assessment steps applicable to the final production scopes before broad public launch of the relevant Google integration.

Security Certifications

Current public claim: EbaSaiyo does not claim SOC 2, ISO 27001, PCI DSS, HIPAA, or similar certification unless a current certification is expressly published here.

Using infrastructure vendors that hold certifications does not itself make EbaSaiyo certified.

Responsible Disclosure

Researchers who believe they have found a vulnerability should contact contact@ebasaiyo.com with sufficient detail for reproduction. Do not access, alter, retain, or disclose data belonging to other customers beyond the minimum necessary to demonstrate a vulnerability.

Subprocessors

See the Subprocessors page for providers used to operate EbaSaiyo and how they relate to Customer data.