Security & Compliance

We built Sibell to withstand scrutiny from CISO, Compliance and Procurement teams from day one. Here you'll find our Trust Pack: the document that answers the questions your legal and security team will ask.

Google Cloud infrastructure TLS 1.2+ end-to-end AES-256 at rest OTP with SHA-256 + salt Ley 1581 / Habeas Data

Sibell Trust Pack — v1.0

PDF Document · ~12 pages · For CISO, Compliance and Procurement Teams

Download PDF

What We Deliver by Default

Built on Google Cloud

The entire platform runs on Google Cloud Platform, inheriting its certified controls (ISO 27001, SOC 2) at the infrastructure level. Sibell operates no servers of its own.

Data Processor

We operate as Processor under Ley 1581 of 2012. The client remains the Controller of their end users' data. Data retention and deletion defined per category.

Rate limiting & kill-switch

Per-client and per-destination rate limits to prevent abuse, with a kill-switch that stops traffic on anomalous patterns. Multi-tenant model with configurable caps.

Encryption & OTP Hashing

TLS 1.2+ in transit, AES-256 at rest, OTPs with SHA-256 + salt — never in plaintext.

DPA Ready from Day One

Data Processing Agreement as an approved template, without heavy negotiation. Available upon request.

Transparent Sub-processors

Public list of sub-processors with 15-day notice for changes. No surprises.

Incident Notification ≤ 72h

Internal incident management policy with P1-P4 classification and notification to affected client within 72 hours.

Operational Auditability

Persistent audit logs in PostgreSQL per verification, endpoint /metrics/providers and CSV exportable reports from the Dashboard.

What's Included in the Trust Pack

Eleven sections covering what your security team will ask about:

  1. Corporate identification and service lines
  2. Legal framework and Processor positioning
  3. Security architecture (infra, encryption, access control, abuse protection, observability)
  4. Current list of sub-processors
  5. Incident management policy (classification, notification, continuity)
  6. Data retention and deletion by category
  7. Availability, latency and delivery SLA
  8. Certifications, audits and compliance roadmap
  9. Business continuity plan
  10. Contacts and onboarding procedure
  11. Appendices: applicable regulatory framework and related documents

Related Documents

Talk to Our Team

Do you have specific questions the Pack doesn't cover? Write to us: