Trust
Security
What Sullivam does today to protect your data and your decisions. We describe only what is implemented. Sullivam does not yet hold third-party certifications (such as SOC 2 or ISO 27001).
Protected decisions
- AI interprets; deterministic rules decide whether anything runs on its own.
- When in doubt, an invoice goes to human review, not to rejection or automatic execution.
- Before anything executes, a guard re-checks the conditions against the database.
Separation between organizations
- Every resource belongs to one organization, and every query is filtered by it.
- The organization is derived from the authenticated session, never from what the browser sends.
- Payment accounts are assigned to a single organization on the server.
Access
- Passwords are stored only as hashes.
- Two-factor authentication by email is available.
- Roles per organization: owner, admin and members with limited permissions.
Data and secrets
- Traffic is encrypted with HTTPS.
- Integration credentials (Outlook, for example) are stored encrypted.
- Original documents are kept in private storage, with temporary links.
- Internal logs don't include invoice content, messages or instructions sent to the AI.
- Sullivam never receives or stores card details: payments are processed by the payment provider.
Webhooks and integrations
- Every incoming notification (email, payments) is authenticated with the provider's signature or secret before it is read.
- Notifications are stored before we respond and are processed only once, even if the provider sends them again.
- Files are validated by type, extension and size.
Traceability
- Every important step (intake, extraction, decision, execution, review) is written to an audit log.
- Billed usage is kept in a log that can't be edited: corrections are visible adjustments.
- Each organization decides how long to keep documents, jobs and audit records.
Vendors that process data: subprocessors (in Spanish). Data processing: DPA and privacy policy (both in Spanish).
Found a vulnerability? Write to the legal contact listed in the terms (in Spanish). Do not access or modify other people's data.