Security
Security requirements are defined for each engagement according to the client's systems, data classification, regulatory context, and operating model.
Access requirements are defined with the client, using named accounts, role-based permissions, and time-bound credentials where the platform supports them.
Where possible, automation credentials remain in the client's approved vault, such as UiPath Orchestrator, Azure Key Vault, or AWS Secrets Manager.
Logging is designed around the workflow's audit requirements, including execution status, exceptions, operator actions, and relevant system events.
Hosting region, data flows, and approved subprocessors are documented during solution design and reflected in the applicable agreement.
The release process is agreed with the client and can include peer review, environment promotion, testing evidence, and approval records.
Sensitive actions can be routed to named reviewers according to risk, confidence, value thresholds, and the client's approval policy.
Contracting requirements depend on the engagement. Before access is granted, we document scope, responsibilities, data handling, approved environments, subprocessors, incident contacts, and applicable confidentiality or data-processing terms.
Incident reporting obligations, escalation contacts, evidence handling, and response timelines are defined in the applicable agreement and operating procedure.
Agentic workflows run through policy-guarded tools, with retrieval limited to the knowledge bases you approve and hallucination-sensitive outputs passed through a human-in-the-loop before they affect your systems of record.
For security documentation or a due-diligence request, contact security@sabanatech.com.