Updated September 25, 2026
This page describes how Sabba approaches security; live controls and policies are in our Trust Center, and you can email support@sabba.ai with questions or vulnerability reports.
Sabba's SOC 2 Type II examination is in progress, and we do not yet have a SOC 2 report. Reports and compliance documentation are available in our Trust Center.
We have not completed a third-party penetration test, do not hold ISO certification, and do not run a paid bug bounty program.
Our subprocessors are published on our Trust Center. Some CloudFront distributions accept plain HTTP as well as HTTPS and are not HTTPS-only; two of the three still allow TLS 1.0.
Sensitive routes require authentication and server-side authorization; role-based access and related practices are summarized in our Trust Center.
We develop in private repositories and deploy changes through reviewed pull requests; build and change-management details are in our Trust Center.
What we collect and how long we keep it is described in our Privacy Policy, Terms of Service, and Human Data Governance Standard. Sabba Praxis sessions use AI personas for voice simulations—do not include real patient information in roleplay.
You can request account deletion from Settings → Account or by emailing support@sabba.ai. Our Privacy Policy describes your data rights and how deletion works.
If you believe you have found a security issue, email support@sabba.ai with “Security” in the subject line, a clear description, and steps to reproduce. Please give us reasonable time to investigate and address the issue before any public disclosure.