Trust

Security at Saetta

Saetta handles your HaloPSA tickets and your customers' messages. These are the safeguards that protect them.

Identity

  • You sign in with Microsoft Entra ID. Saetta has no passwords of its own.
  • Multi-factor authentication and Conditional Access come from your own Microsoft 365 policies.
  • Only owners and admins can change settings, link technicians or manage billing.

Data protection

  • All traffic is encrypted in transit with TLS.
  • HaloPSA and carrier credentials are encrypted at rest with AES-256-GCM.
  • Every record is scoped to its MSP tenant, and every request is checked against that tenant.
  • HaloPSA data is fetched on demand rather than copied. Attachments stream through short-lived signed links.
  • Your data is never used to train AI models. AI features run only when a technician uses them.

Connected services

  • Webhooks from HaloPSA, SMS carriers and our payment processor are authenticated. Unauthenticated requests are rejected.
  • Saetta uses the HaloPSA API permissions you grant, through an API application you control and can revoke at any time.

Operations

  • Edge DDoS protection and per-client rate limiting.
  • Error monitoring with message content, credentials and request bodies excluded.
  • Automated health checks on the application and database.
  • Dependency updates and secret scanning on every change.

Compliance

We act as a processor for your Customer Data. A DPA is available. See our subprocessors. SOC 2 is on our roadmap.

Report a vulnerability

Email security@saetta.io (also listed in security.txt). Please give us reasonable time to fix an issue before disclosing it. We don't pursue good-faith research that respects user privacy and avoids service disruption.