Security & Compliance

We built Sibell to withstand scrutiny from CISO, Compliance and Procurement teams from day one. Here you'll find our Trust Pack: the document that answers the questions your legal and security team will ask.

TLS 1.2+ end-to-end AES-256 at rest OTP with SHA-256 + salt Ley 1581 / Habeas Data

Sibell Trust Pack — v1.0

PDF Document · ~12 pages · For CISO, Compliance and Procurement Teams

Download PDF

What We Deliver by Default

Data Processor

We operate as Processor under Ley 1581 of 2012. The client remains the Controller of their end users' data.

Encryption & OTP Hashing

TLS 1.2+ in transit, AES-256 at rest, OTPs with SHA-256 + salt — never in plaintext.

DPA Ready from Day One

Data Processing Agreement as an approved template, without heavy negotiation. Available upon request.

Transparent Sub-processors

Public list of sub-processors with 15-day notice for changes. No surprises.

Incident Notification ≤ 72h

Internal incident management policy with P1-P4 classification and notification to affected client within 72 hours.

Operational Auditability

Persistent logs per verification, endpoint /metrics/providers and CSV exportable reports from the Dashboard.

What's Included in the Trust Pack

Eleven sections covering what your security team will ask about:

  1. Corporate identification and service lines
  2. Legal framework and Processor positioning
  3. Security architecture (infra, encryption, access control, abuse protection, observability)
  4. Current list of sub-processors
  5. Incident management policy (classification, notification, continuity)
  6. Data retention and deletion by category
  7. Availability, latency and delivery SLA
  8. Certifications, audits and compliance roadmap
  9. Business continuity plan
  10. Contacts and onboarding procedure
  11. Appendices: applicable regulatory framework and related documents

Related Documents

Talk to Our Team

Do you have specific questions the Pack doesn't cover? Write to us: