Security and privacy are foundational to SaibaCRM. This page summarises the technical and organisational measures we use to protect your data. It complements our Privacy Policy.
SaibaCRM is multi-tenant with strict tenant isolation — every record is scoped to its tenant and tenants can never read each other's data. Operational personal data is stored in the data region for your country (for example, UAE customers are served from a UAE data store) to support data residency requirements.
We follow secure development practices aligned with the OWASP Top 10, including protection against injection, broken access control and cross-site attacks. Input is validated server-side and tenant scope is enforced on every request.
Payments are processed by our PCI-DSS compliant payment partner. We do not store card numbers or sensitive payment credentials on our servers.
Data is backed up regularly to enable recovery in the event of an incident. We monitor our systems for availability and integrity.
We welcome responsible disclosure. If you believe you've found a security vulnerability, please contact us so we can investigate and respond promptly. Please do not publicly disclose the issue until it has been resolved.
Security & privacy: privacy@saibacrm.com
Support: support@saibacrm.com