Trust

    Security and trust

    Last reviewed 18 August 2026

    Sailsrep AB runs an information security management system certified to ISO/IEC 27001:2022. This page carries what a security review asks for, and anything beyond it is sent on request.

    ISO/IEC 27001:2022

    Granted by SBCERT after a two-stage audit in June 2026, with surveillance audits on the standard cycle.

    ItemDetail
    StandardISO/IEC 27001:2022
    Certificate holderSailsrep AB
    Certification bodySBCERT
    AccreditationSWEDAC, accreditation number 10127
    Certificate issued25 June 2026
    Certificate copyAvailable on request from the contact below.

    The certified management system covers the Sailsrep platform and the company operations that build and run it. The certificate and our Statement of Applicability are available on request.

    Where customer data is held

    Customer data is hosted in the European Union. Processing outside the EU is done by the companies named in our subprocessor list, with the safeguards described there.

    Controls

    AreaWhat we do
    EncryptionCustomer data is encrypted in transit and at rest.
    Access controlRole based, least privilege, multi-factor authentication, reviewed periodically.
    Tenant separationEach customer's data is logically separated and access is scoped to that customer.
    Logging and monitoringSystem and access activity is logged centrally and monitored, with alerting.
    BackupsRegular, encrypted, with restores tested.

    Artificial intelligence

    Prompts and product data are processed by enterprise AI providers under data processing terms. Under those terms your content is not used to train their models. Those providers are named in our subprocessor list, and the regions they process in are stated there.

    Incidents

    We keep a documented incident response process with defined roles, severity levels and post-incident review. If a personal data breach affects your data we notify you without undue delay, with what you need for your own GDPR reporting.

    Subprocessors and data processing

    The companies that process data on our behalf, what each one does and where it sits, are in our subprocessor list. Our privacy policy covers legal basis, retention and your rights, and a data processing agreement is available on request.

    Contact

    For a security questionnaire, the certificate, our Statement of Applicability or a data processing agreement, write to us and say which you need. Deployment options are discussed during evaluation.