Last updated: August 11, 2026
Saazly processes customer communications. Our security practices are built on data minimization, access control, and separation between customer workspaces. This page provides an overview and does not guarantee that incidents can never occur.
Security areas
- Identity and access: personal accounts, roles, and workspace memberships are used to control access.
- Data in transit: web and API traffic must use TLS.
- Isolation: the server must verify current access permissions for the workspace and conversation.
- Operations: logging and error information must be minimized and must not intentionally contain secrets.
- Providers: external services are assessed based on functionality, data protection, and contractual terms.
Report a vulnerability
Send your report to [email protected] with the affected URL or app version, clear reproduction steps, potential impact, and the minimum proof of concept required.
- Use your own test accounts and stop once you have sufficient evidence.
- Do not send passwords, tokens, entire databases, or more personal data than necessary.
- Do not engage in social engineering, phishing, denial of service, spam, malware, persistent access, or unauthorized testing of third parties.
- If you inadvertently access another customer’s data, stop immediately, do not collect anything further, and contact us.
We handle good-faith reports and aim to keep reporters informed. No bug bounty or specific safe harbor is offered unless confirmed in writing for the report in question.