SM Sabeemod
Access workspace
Security whitepaper

How your data stays safe.

The technical and organisational measures we implement, in plain English. Written to be readable by a hotel general manager, not only by a CISO.

Certifications and audits

  • ISO 27001 hosting infrastructure (Frankfurt and Amsterdam regions).
  • SOC 2 Type II audited annually by a Big Four auditor.
  • GDPR compliance framework, DPA published on the /dpa page.
  • Annual penetration test by an independent third party (report shared on NDA request to sales@sabeemod.org).
  • Registration with the Montenegrin data-protection regulator AZLP, reg. no. 05-030/24-1938.

Encryption

All traffic is encrypted in transit with TLS 1.2 minimum and TLS 1.3 where the client supports it. HSTS is enforced with a one-year max-age and preload. Data at rest is encrypted with AES-256 on databases, on object storage and on backups. Encryption keys are stored inside a hardware security module operated in Frankfurt, rotated every ninety days.

Access control

Every employee account has mandatory multi-factor authentication (hardware key preferred, TOTP accepted). Access to production systems is role-based and reviewed quarterly. Access is revoked automatically within thirty minutes of an employee's departure being registered in the HR system. Session tokens for the workspace application are refreshed hourly; idle sessions expire after eight hours.

Logging and monitoring

Every consequential action inside the workspace is written to an append-only audit log, retained for twelve months. A security-information-and-event-management system watches the logs for anomalies (unusual sign-in geography, brute-force attempts, unexpected API scope changes). Alerts are triaged by an on-call engineer within thirty minutes, twenty-four hours a day.

Backup and business continuity

Full backups run nightly, incremental backups run hourly. Restoration drills are executed twice a year on the exact production dataset, with signed evidence archived. The business continuity plan targets a four-hour recovery-time objective and a one-hour recovery-point objective, and is tested annually against a realistic failure scenario (full region loss).

Vulnerability management

Automated vulnerability scans run daily on every host and every container image. Critical vulnerabilities (CVSS 9+) are patched within seven days; high vulnerabilities within thirty days. A public coordinated vulnerability disclosure programme runs at security@sabeemod.org; researchers acting in good faith and respecting our disclosure guidelines will not be pursued under Montenegrin computer-misuse legislation.

Incident response

Sabeemod maintains a written incident-response plan with a two-hour internal notification target and a seventy-two-hour customer notification target for personal data breaches (Article 33 GDPR). Post-incident write-ups are shared with affected customers, and public post-mortems are published on the /changelog page when the incident is systemically informative.

Personnel

Every new employee undergoes background checks appropriate to their role, signs a written confidentiality agreement and completes a security induction covering the incident-response plan, the Acceptable Use Policy and the code of conduct. Ongoing security training runs annually, with phishing exercises quarterly.

Sub-processors

The complete sub-processor register is published in the /dpa page and updated whenever a processor is added or replaced, with thirty days' prior notice to customers who subscribe to that notice.

PGP key

Sensitive reports and coordinated vulnerability disclosures can be encrypted with the following PGP key: 0x8B4D 22C1 61FA 88E3 6C6E 03A2 4C41 9F8D E71B 8A14. Fingerprint verification is available on request.

Request the full SOC 2 report