Last updated: 1st February 2026
At Sahl, we treat financial data with the seriousness it deserves. Not because it's a slogan, but because Open Banking only works when users stay in control, and partners can verify how data is protected.
Legal Note
This Trust Center is for transparency and does not, by itself, create contractual obligations. If you have a signed agreement with Sahl (MSA/API Agreement/DPA), that agreement governs if anything differs.
At a Glance
Consent-first access
Data access begins with explicit authorization and can be revoked.
Minimized data
We pull and process only what is needed for the approved purpose.
Encryption
Industry-standard protections in transit and at rest.
Least privilege
Strict access controls for people and systems.
Monitoring & traceability
Logs and audit trails support accountability.
Secure SDLC
Review, testing, change control, and vulnerability management.
Vendor governance
Sub-processors are assessed and contractually bound.
Incident readiness
Documented playbooks and communication paths.
CNDP posture
Formal declarations and transfer governance.
Trust Model
Sahl provides APIs, dashboards, and processing capabilities that help regulated institutions and fintechs build secure financial journeys.
We are not a bank. We do not hold customer funds.
In enterprise contexts, our customer/partner typically determines the purpose of processing (often acting as a controller), and Sahl processes data on their documented instructions (often acting as a processor).
For our website and direct communications, Sahl typically acts as a controller for that specific processing.
Compliance & Governance
Standards and principles we align with
PSD2-style security expectations
Secure communication, strong authentication patterns, fraud resistance, and auditability.
GDPR-aligned privacy principles
Lawfulness, transparency, minimization, purpose limitation, storage limitation, integrity/confidentiality, and accountability.
Morocco (CNDP / Law 09-08)
User rights and formal governance for processing declarations and cross-border transfers.
CNDP References
Sahl maintains CNDP governance for personal data processing and transfers. CNDP receipts (declaration and transfer) can be provided upon request.
Sahl CPU (Consent & Privacy Unit)
Our internal function responsible for aligning product decisions with privacy, consent, and security, especially for sensitive workflows like onboarding, KYC, underwriting, and Open Banking data access.
Consent governance
Clear consent design, consent records, revocation flows.
Privacy operations
Records of processing, privacy impact review, data subject rights.
Security coordination
Risk review, vendor privacy review, incident coordination.
Security Controls Matrix
Designed to map to common security questionnaires and ISO-style control domains, without implying certification.
| Domain | What we implement |
|---|---|
| Governance & Risk | Security ownership, policies, vendor governance. |
| Asset & Data Management | Data mapping, classification, retention. |
| Human Security | Training, access controls, least privilege. |
| Identity & Access | RBAC, MFA, access reviews. |
| Cryptography | TLS/HTTPS, encryption at rest. |
| Secure SDLC | Code review, CI/CD checks. |
| Logging & Monitoring | Centralized logs, alerting. |
| Vulnerability Management | Scanning, prioritized remediation. |
| Incident Response | Detection → containment → remediation. |
| Business Continuity | Backups, recovery, runbooks. |
| Supplier Security | Vendor due diligence. |
| Compliance & Privacy | CNDP governance, GDPR-style principles. |
If you need a control-by-control security questionnaire answered, send it to contact@sahlfinancial.com. We'll respond with the most current evidence pack under NDA where appropriate.
Data Processing Addendum (DPA) Summary
This section summarizes typical DPA concepts customers expect. The full signed DPA governs.
What this means in practice
- Sahl processes Customer Data only on documented instructions, unless otherwise required by law.
- We apply appropriate technical and organizational measures to protect data.
- We use sub-processors to run infrastructure, under contractual protections.
- We support data subject requests by routing them to the controller and assisting as a processor.
- We provide breach/incident communication consistent with contractual and legal requirements.
- At end of services, we support deletion/return of Customer Data per contract.
Detailed DPA-style clauses (summary)
Retention Schedule
Retention can be configured per contract / product.
User rights requests: We aim to respond within a reasonable period and as required by applicable law. If Sahl is a processor, requests are typically fulfilled via the controller.
| Data category | Typical purpose | Default retention | Notes / configurable? |
|---|---|---|---|
| Website contact forms / leads | Responding to inquiries | 12-24 months | Deleted sooner upon request where feasible |
| Marketing communications | Product updates | Until opt-out | Consent/opt-out honored where required |
| Customer support tickets | Support + audit trail | 24-36 months | May be longer for legal disputes |
| Platform account metadata | Service delivery | Contract term + 12 months | Configurable |
| Open Banking connection logs | Security + troubleshooting | 12-24 months | Minimization applied |
| Raw financial data | Service delivery | Configurable (90-365 days) | Driven by use-case + contract |
| Derived insights | Product features | Configurable (6-24 months) | Often less sensitive than raw |
| Security logs | Detection/investigation | 12-24 months | May be extended for investigations |
| Backups | Resilience | 30-90 days | Depends on system criticality |
| Legal/compliance records | Legal obligations | As required by law | Narrowly scoped |
Responsible Disclosure Policy
We welcome security research performed responsibly. If you believe you've found a vulnerability, please report it privately so we can fix it quickly.
Report to
Subject: Security Disclosure
What to include
- • A clear description of the issue and potential impact
- • Steps to reproduce (proof-of-concept if possible)
- • Affected URLs/endpoints/systems (if known)
- • Screenshots/logs (if helpful)
- • Your contact info for follow-ups
Safe-harbor (good-faith testing)
We consider research authorized under this policy when you make a good-faith effort to avoid privacy violations, service disruption, and data destruction. Test only on accounts/systems you own or are authorized to test. Do not access or exfiltrate more data than necessary. Do not publicly disclose details until we've had a reasonable opportunity to remediate.
Out of scope
Denial of service (DoS/DDoS), spam, or automated scanning that degrades service. Social engineering, phishing, or physical security attacks. Issues solely in third-party systems not under Sahl's control.
Our commitment: We will acknowledge receipt and route to the right team. We will investigate, remediate where appropriate, and keep communication professional and constructive.
Need a security pack?
Policies, architecture overview, sub-processor summary, DPA, questionnaires