Tenant boundaries keep one workspace’s project data separate from another.
Security and privacy
Trust comes from how the product behaves.
SEBAI uses workspace boundaries, authenticated access, role controls, and deliberate data handling to support secure project delivery. This page describes implemented behavior, not aspirational certifications.
Ask a security questionAuthentication, CSRF protection, roles, and permissions guard protected actions.
Private attachments and approved publication paths reduce accidental exposure.
Tenant boundaries
SEBAI separates work by workspace and enforces tenant-scoped access in the application. Customer workspace data is not used to populate the public website.
Authentication and protected changes
Authenticated sessions use an HttpOnly session cookie. Authenticated state-changing requests use CSRF protection. The public website does not collect login credentials.
Roles, permissions, and attachments
Workspaces include role and permission controls. Attachments remain private and are served only through authenticated authorization checks.
Payment collection
Stripe Checkout collects payment details. SEBAI does not collect card details in its own frontend.
AI data handling
AI features run only when invoked by an authenticated user. Email addresses and phone-number-like values are redacted before prompts are built as a defense-in-depth measure. Request logs avoid raw prompts and provider responses; audit data follows the application’s documented handling policy.
Careful, factual communication
What we are not claiming here
This page does not claim SOC 2, ISO 27001, HIPAA or GDPR compliance, zero data retention, specific encryption guarantees, penetration testing, or uptime guarantees. Contact SEBAI if your evaluation requires current evidence for a specific control.
Contact SEBAIMake work easier to follow
Give your next project a calmer place to land.
Bring plans, tickets, teams, sprints, releases, and delivery views into one structured workspace.