Sailsrep AB runs an information security management system certified to ISO/IEC 27001:2022. This page carries what a security review asks for, and anything beyond it is sent on request.
ISO/IEC 27001:2022
Granted by SBCERT after a two-stage audit in June 2026, with surveillance audits on the standard cycle.
| Item | Detail |
|---|---|
| Standard | ISO/IEC 27001:2022 |
| Certificate holder | Sailsrep AB |
| Certification body | SBCERT |
| Accreditation | SWEDAC, accreditation number 10127 |
| Certificate issued | 25 June 2026 |
| Certificate copy | Available on request from the contact below. |
The certified management system covers the Sailsrep platform and the company operations that build and run it. The certificate and our Statement of Applicability are available on request.
Where customer data is held
Customer data is hosted in the European Union. Processing outside the EU is done by the companies named in our subprocessor list, with the safeguards described there.
Controls
| Area | What we do |
|---|---|
| Encryption | Customer data is encrypted in transit and at rest. |
| Access control | Role based, least privilege, multi-factor authentication, reviewed periodically. |
| Tenant separation | Each customer's data is logically separated and access is scoped to that customer. |
| Logging and monitoring | System and access activity is logged centrally and monitored, with alerting. |
| Backups | Regular, encrypted, with restores tested. |
Artificial intelligence
Prompts and product data are processed by enterprise AI providers under data processing terms. Under those terms your content is not used to train their models. Those providers are named in our subprocessor list, and the regions they process in are stated there.
Incidents
We keep a documented incident response process with defined roles, severity levels and post-incident review. If a personal data breach affects your data we notify you without undue delay, with what you need for your own GDPR reporting.
Subprocessors and data processing
The companies that process data on our behalf, what each one does and where it sits, are in our subprocessor list. Our privacy policy covers legal basis, retention and your rights, and a data processing agreement is available on request.
Contact
For a security questionnaire, the certificate, our Statement of Applicability or a data processing agreement, write to us and say which you need. Deployment options are discussed during evaluation.
- Security and privacy contact: privacy@sailsrep.ai
- To report a vulnerability, write to privacy@sailsrep.ai. Please do not test against a customer’s live environment.