EbaSaiyoBack to EbaSaiyo

Security & Trust

Last updated: 8 August 2026

Last updated: 8 August 2026

EbaSaiyo connects to business communications and may process sensitive operational data. Trust is therefore a core product requirement.

This page is designed to state what EbaSaiyo actually does without claiming certifications or controls that have not been independently verified.

Security at a Glance

EbaSaiyo's application design includes:

  • authenticated user access;
  • organization-level tenant isolation;
  • AI Employee resource scoping;
  • delegated OAuth integrations for supported email providers;
  • encrypted storage of sensitive OAuth credentials;
  • server-side secret handling;
  • HTTPS/TLS transport security;
  • AI decision logging for autonomous behavior;
  • human-configurable autonomy and override controls; and
  • business-rule and escalation safeguards for AI communications.

Authentication

EbaSaiyo uses a specialized identity provider for user authentication and session management. Workspace and application authorization are enforced separately so authentication alone does not grant access to another organization's data.

Customers are responsible for protecting their own identity-provider accounts and devices. MFA availability may depend on identity-provider and plan configuration.

Tenant Isolation

Customer data is associated with an Organization/Workspace. Application endpoints must verify the authenticated user's membership before accessing tenant data.

AI Employees, email connections, messages, drafts, and settings are intended to be scoped through the Customer's organization so identifiers alone do not authorize access.

Email Integrations

EbaSaiyo supports OAuth-based integrations with supported email providers rather than asking customers to provide their normal mailbox password.

For Microsoft Graph, EbaSaiyo's intended architecture uses delegated permissions, so the Service acts on behalf of the authorized user within permissions granted through Microsoft.

For Google Workspace/Gmail, EbaSaiyo is designed to request only permissions needed for customer-facing email features and to comply with Google's applicable API user-data requirements.

OAuth Credential Protection

Sensitive OAuth credentials are stored server-side. The current application architecture encrypts email-provider tokens at rest using authenticated encryption rather than storing them as plaintext application fields.

Production key management, access permissions, and rotation procedures should be maintained as part of EbaSaiyo's internal security program.

AI Safety and Control

AI Employees may operate in different autonomy modes. Safety controls include, depending on configuration:

  • Manual human approval;
  • confidence-based gating;
  • configurable business rules;
  • escalation to a human;
  • no-reply/ignore classification;
  • audit records of AI decisions;
  • human override; and
  • ability to reduce autonomy or disable a connection.

A confidence indicator is not a guarantee that AI output is correct.

Data Used for AI

EbaSaiyo may send relevant Customer Content to an API-based AI provider to provide enabled features.

Where OpenAI's API platform is used, OpenAI states that business/API inputs and outputs are not used to train its models by default unless the customer explicitly opts in to sharing. Provider-specific abuse-monitoring and retention controls may still apply.

EbaSaiyo does not intentionally opt Customer Content into general model training without appropriate customer agreement and disclosure.

Encryption

EbaSaiyo is designed to use:

  • TLS/HTTPS for data in transit; and
  • authenticated encryption for sensitive stored integration credentials.

Database-level encryption, infrastructure encryption, and backup encryption may also be provided by EbaSaiyo's cloud vendors under their respective security programs. Exact production controls should be verified against current vendor documentation and contracts.

Infrastructure

EbaSaiyo uses third-party cloud infrastructure and SaaS providers for hosting, database, authentication, AI processing, and other functions. A current list appears in the Subprocessors disclosure.

EbaSaiyo evaluates access and architecture to minimize unnecessary exposure of Customer Content.

Logging and Auditability

EbaSaiyo records application and operational events needed for troubleshooting and security. AI decision logs may include the AI Employee, selected action, autonomy context, confidence information, triggered rules, and human overrides.

EbaSaiyo seeks to avoid unnecessary logging of secrets such as access and refresh tokens.

Incident Response

EbaSaiyo maintains or will maintain a documented incident-response process for triage, containment, remediation, recovery, and customer notification.

Confirmed Personal Data Breaches affecting Customer Personal Data will be communicated without undue delay as required by applicable law and the Data Processing Addendum.

Security issues can be reported to: contact@ebasaiyo.com.

Data Retention and Deletion

Customer Content is retained only as needed to operate the Service, meet contractual commitments, support security, and satisfy legal obligations.

Upon account termination or valid deletion instruction, data is deleted according to EbaSaiyo's deletion workflow and backup lifecycle, subject to legal retention requirements.

Exact production retention periods should be published once the launch configuration is finalized.

Privacy and GDPR

EbaSaiyo is designed for business customers that may operate in the European Economic Area. Where EbaSaiyo processes Customer Personal Data on behalf of a customer, the Data Processing Addendum is intended to address GDPR Article 28 obligations.

International transfers are handled using legally recognized mechanisms where required, such as adequacy decisions or Standard Contractual Clauses.

EU AI Act

The EU Artificial Intelligence Act applies in substantial part from 2 August 2026. EbaSaiyo treats AI transparency and human control as product requirements.

Customers using AI Employees to interact directly with individuals are responsible for determining whether an AI disclosure is required for their use case and for ensuring required transparency is provided.

Google API Compliance

Google classifies some Gmail API permissions as sensitive or restricted. Apps that store or transmit restricted-scope data may be subject to OAuth verification and security assessment requirements.

EbaSaiyo must complete all verification and assessment steps applicable to the final production scopes before broad public launch of the relevant Google integration.

Security Certifications

Current public claim: EbaSaiyo does not claim SOC 2, ISO 27001, PCI DSS, HIPAA, or similar certification unless a current certification is expressly published here.

Using infrastructure vendors that hold certifications does not itself make EbaSaiyo certified.

Responsible Disclosure

Researchers who believe they have found a vulnerability should contact contact@ebasaiyo.com with sufficient detail for reproduction. Do not access, alter, retain, or disclose data belonging to other customers beyond the minimum necessary to demonstrate a vulnerability.

Subprocessors

See Subprocessors.md for providers used to operate EbaSaiyo and how they relate to Customer data.