Trust Center

    Security

    Last updated: 1st February 2026

    At Sahl, we treat financial data with the seriousness it deserves. Not because it's a slogan, but because Open Banking only works when users stay in control, and partners can verify how data is protected.

    PSD2-style security GDPR-grade privacy CNDP (Law 09-08) compliant

    Legal Note

    This Trust Center is for transparency and does not, by itself, create contractual obligations. If you have a signed agreement with Sahl (MSA/API Agreement/DPA), that agreement governs if anything differs.

    At a Glance

    Consent-first access

    Data access begins with explicit authorization and can be revoked.

    Minimized data

    We pull and process only what is needed for the approved purpose.

    Encryption

    Industry-standard protections in transit and at rest.

    Least privilege

    Strict access controls for people and systems.

    Monitoring & traceability

    Logs and audit trails support accountability.

    Secure SDLC

    Review, testing, change control, and vulnerability management.

    Vendor governance

    Sub-processors are assessed and contractually bound.

    Incident readiness

    Documented playbooks and communication paths.

    CNDP posture

    Formal declarations and transfer governance.

    Trust Model

    Sahl provides APIs, dashboards, and processing capabilities that help regulated institutions and fintechs build secure financial journeys.

    We are not a bank. We do not hold customer funds.

    In enterprise contexts, our customer/partner typically determines the purpose of processing (often acting as a controller), and Sahl processes data on their documented instructions (often acting as a processor).

    For our website and direct communications, Sahl typically acts as a controller for that specific processing.

    Compliance & Governance

    Standards and principles we align with

    PSD2-style security expectations

    Secure communication, strong authentication patterns, fraud resistance, and auditability.

    GDPR-aligned privacy principles

    Lawfulness, transparency, minimization, purpose limitation, storage limitation, integrity/confidentiality, and accountability.

    Morocco (CNDP / Law 09-08)

    User rights and formal governance for processing declarations and cross-border transfers.

    CNDP References

    Sahl maintains CNDP governance for personal data processing and transfers. CNDP receipts (declaration and transfer) can be provided upon request.

    Sahl CPU (Consent & Privacy Unit)

    Our internal function responsible for aligning product decisions with privacy, consent, and security, especially for sensitive workflows like onboarding, KYC, underwriting, and Open Banking data access.

    Consent governance

    Clear consent design, consent records, revocation flows.

    Privacy operations

    Records of processing, privacy impact review, data subject rights.

    Security coordination

    Risk review, vendor privacy review, incident coordination.

    Security Controls Matrix

    Designed to map to common security questionnaires and ISO-style control domains, without implying certification.

    Show conciseShow detailed
    DomainWhat we implement
    Governance & RiskSecurity ownership, policies, vendor governance.
    Asset & Data ManagementData mapping, classification, retention.
    Human SecurityTraining, access controls, least privilege.
    Identity & AccessRBAC, MFA, access reviews.
    CryptographyTLS/HTTPS, encryption at rest.
    Secure SDLCCode review, CI/CD checks.
    Logging & MonitoringCentralized logs, alerting.
    Vulnerability ManagementScanning, prioritized remediation.
    Incident ResponseDetection → containment → remediation.
    Business ContinuityBackups, recovery, runbooks.
    Supplier SecurityVendor due diligence.
    Compliance & PrivacyCNDP governance, GDPR-style principles.

    If you need a control-by-control security questionnaire answered, send it to contact@sahlfinancial.com. We'll respond with the most current evidence pack under NDA where appropriate.

    Data Processing Addendum (DPA) Summary

    This section summarizes typical DPA concepts customers expect. The full signed DPA governs.

    What this means in practice

    • Sahl processes Customer Data only on documented instructions, unless otherwise required by law.
    • We apply appropriate technical and organizational measures to protect data.
    • We use sub-processors to run infrastructure, under contractual protections.
    • We support data subject requests by routing them to the controller and assisting as a processor.
    • We provide breach/incident communication consistent with contractual and legal requirements.
    • At end of services, we support deletion/return of Customer Data per contract.

    Detailed DPA-style clauses (summary)

    Retention Schedule

    Retention can be configured per contract / product.

    User rights requests: We aim to respond within a reasonable period and as required by applicable law. If Sahl is a processor, requests are typically fulfilled via the controller.

    Data categoryTypical purposeDefault retentionNotes / configurable?
    Website contact forms / leadsResponding to inquiries12-24 monthsDeleted sooner upon request where feasible
    Marketing communicationsProduct updatesUntil opt-outConsent/opt-out honored where required
    Customer support ticketsSupport + audit trail24-36 monthsMay be longer for legal disputes
    Platform account metadataService deliveryContract term + 12 monthsConfigurable
    Open Banking connection logsSecurity + troubleshooting12-24 monthsMinimization applied
    Raw financial dataService deliveryConfigurable (90-365 days)Driven by use-case + contract
    Derived insightsProduct featuresConfigurable (6-24 months)Often less sensitive than raw
    Security logsDetection/investigation12-24 monthsMay be extended for investigations
    BackupsResilience30-90 daysDepends on system criticality
    Legal/compliance recordsLegal obligationsAs required by lawNarrowly scoped

    Responsible Disclosure Policy

    We welcome security research performed responsibly. If you believe you've found a vulnerability, please report it privately so we can fix it quickly.

    Report to

    Subject: Security Disclosure

    What to include

    • • A clear description of the issue and potential impact
    • • Steps to reproduce (proof-of-concept if possible)
    • • Affected URLs/endpoints/systems (if known)
    • • Screenshots/logs (if helpful)
    • • Your contact info for follow-ups

    Safe-harbor (good-faith testing)

    We consider research authorized under this policy when you make a good-faith effort to avoid privacy violations, service disruption, and data destruction. Test only on accounts/systems you own or are authorized to test. Do not access or exfiltrate more data than necessary. Do not publicly disclose details until we've had a reasonable opportunity to remediate.

    Out of scope

    Denial of service (DoS/DDoS), spam, or automated scanning that degrades service. Social engineering, phishing, or physical security attacks. Issues solely in third-party systems not under Sahl's control.

    Our commitment: We will acknowledge receipt and route to the right team. We will investigate, remediate where appropriate, and keep communication professional and constructive.

    Need a security pack?

    Policies, architecture overview, sub-processor summary, DPA, questionnaires

    Request Security Pack

    We value your privacy

    We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking 'Accept All', you consent to our use of cookies. Learn more