Security and privacy

Trust comes from how the product behaves.

SEBAI uses workspace boundaries, authenticated access, role controls, and deliberate data handling to support secure project delivery. This page describes implemented behavior, not aspirational certifications.

Ask a security question
Workspace scoped

Tenant boundaries keep one workspace’s project data separate from another.

Access controlled

Authentication, CSRF protection, roles, and permissions guard protected actions.

Deliberate sharing

Private attachments and approved publication paths reduce accidental exposure.

01

Tenant boundaries

SEBAI separates work by workspace and enforces tenant-scoped access in the application. Customer workspace data is not used to populate the public website.

02

Authentication and protected changes

Authenticated sessions use an HttpOnly session cookie. Authenticated state-changing requests use CSRF protection. The public website does not collect login credentials.

03

Roles, permissions, and attachments

Workspaces include role and permission controls. Attachments remain private and are served only through authenticated authorization checks.

04

Payment collection

Stripe Checkout collects payment details. SEBAI does not collect card details in its own frontend.

05

AI data handling

AI features run only when invoked by an authenticated user. Email addresses and phone-number-like values are redacted before prompts are built as a defense-in-depth measure. Request logs avoid raw prompts and provider responses; audit data follows the application’s documented handling policy.

Careful, factual communication

What we are not claiming here

This page does not claim SOC 2, ISO 27001, HIPAA or GDPR compliance, zero data retention, specific encryption guarantees, penetration testing, or uptime guarantees. Contact SEBAI if your evaluation requires current evidence for a specific control.

Contact SEBAI

Make work easier to follow

Give your next project a calmer place to land.

Bring plans, tickets, teams, sprints, releases, and delivery views into one structured workspace.