Trust

Security

What Sullivam does today to protect your data and your decisions. We describe only what is implemented. Sullivam does not yet hold third-party certifications (such as SOC 2 or ISO 27001).

Protected decisions

  • AI interprets; deterministic rules decide whether anything runs on its own.
  • When in doubt, an invoice goes to human review, not to rejection or automatic execution.
  • Before anything executes, a guard re-checks the conditions against the database.

Separation between organizations

  • Every resource belongs to one organization, and every query is filtered by it.
  • The organization is derived from the authenticated session, never from what the browser sends.
  • Payment accounts are assigned to a single organization on the server.

Access

  • Passwords are stored only as hashes.
  • Two-factor authentication by email is available.
  • Roles per organization: owner, admin and members with limited permissions.

Data and secrets

  • Traffic is encrypted with HTTPS.
  • Integration credentials (Outlook, for example) are stored encrypted.
  • Original documents are kept in private storage, with temporary links.
  • Internal logs don't include invoice content, messages or instructions sent to the AI.
  • Sullivam never receives or stores card details: payments are processed by the payment provider.

Webhooks and integrations

  • Every incoming notification (email, payments) is authenticated with the provider's signature or secret before it is read.
  • Notifications are stored before we respond and are processed only once, even if the provider sends them again.
  • Files are validated by type, extension and size.

Traceability

  • Every important step (intake, extraction, decision, execution, review) is written to an audit log.
  • Billed usage is kept in a log that can't be edited: corrections are visible adjustments.
  • Each organization decides how long to keep documents, jobs and audit records.

Vendors that process data: subprocessors (in Spanish). Data processing: DPA and privacy policy (both in Spanish).

Found a vulnerability? Write to the legal contact listed in the terms (in Spanish). Do not access or modify other people's data.