Sabba

Security at Sabba

Updated September 25, 2026

This page describes how Sabba approaches security; live controls and policies are in our Trust Center, and you can email support@sabba.ai with questions or vulnerability reports.

Certifications and third-party assessments

Sabba's SOC 2 Type II examination is in progress, and we do not yet have a SOC 2 report. Reports and compliance documentation are available in our Trust Center.

We have not completed a third-party penetration test, do not hold ISO certification, and do not run a paid bug bounty program.

Infrastructure and data security

Our subprocessors are published on our Trust Center. Some CloudFront distributions accept plain HTTP as well as HTTPS and are not HTTPS-only; two of the three still allow TLS 1.0.

Application and access security

Sensitive routes require authentication and server-side authorization; role-based access and related practices are summarized in our Trust Center.

How we build

We develop in private repositories and deploy changes through reviewed pull requests; build and change-management details are in our Trust Center.

Data handling and retention

What we collect and how long we keep it is described in our Privacy Policy, Terms of Service, and Human Data Governance Standard. Sabba Praxis sessions use AI personas for voice simulations—do not include real patient information in roleplay.

Account deletion

You can request account deletion from Settings → Account or by emailing support@sabba.ai. Our Privacy Policy describes your data rights and how deletion works.

Vulnerability disclosure

If you believe you have found a security issue, email support@sabba.ai with “Security” in the subject line, a clear description, and steps to reproduce. Please give us reasonable time to investigate and address the issue before any public disclosure.

    Sabba • Security