We built Sibell to withstand scrutiny from CISO, Compliance and Procurement teams from day one. Here you'll find our Trust Pack: the document that answers the questions your legal and security team will ask.
PDF Document · ~12 pages · For CISO, Compliance and Procurement Teams
The entire platform runs on Google Cloud Platform, inheriting its certified controls (ISO 27001, SOC 2) at the infrastructure level. Sibell operates no servers of its own.
We operate as Processor under Ley 1581 of 2012. The client remains the Controller of their end users' data. Data retention and deletion defined per category.
Per-client and per-destination rate limits to prevent abuse, with a kill-switch that stops traffic on anomalous patterns. Multi-tenant model with configurable caps.
TLS 1.2+ in transit, AES-256 at rest, OTPs with SHA-256 + salt — never in plaintext.
Data Processing Agreement as an approved template, without heavy negotiation. Available upon request.
Public list of sub-processors with 15-day notice for changes. No surprises.
Internal incident management policy with P1-P4 classification and notification to affected client within 72 hours.
Persistent audit logs in PostgreSQL per verification, endpoint /metrics/providers and CSV exportable reports from the Dashboard.
Eleven sections covering what your security team will ask about:
Do you have specific questions the Pack doesn't cover? Write to us: