Trust
Security at Saetta
Saetta handles your HaloPSA tickets and your customers' messages. These are the safeguards that protect them.
Identity
- You sign in with Microsoft Entra ID. Saetta has no passwords of its own.
- Multi-factor authentication and Conditional Access come from your own Microsoft 365 policies.
- Only owners and admins can change settings, link technicians or manage billing.
Data protection
- All traffic is encrypted in transit with TLS.
- HaloPSA and carrier credentials are encrypted at rest with AES-256-GCM.
- Every record is scoped to its MSP tenant, and every request is checked against that tenant.
- HaloPSA data is fetched on demand rather than copied. Attachments stream through short-lived signed links.
- Your data is never used to train AI models. AI features run only when a technician uses them.
Connected services
- Webhooks from HaloPSA, SMS carriers and our payment processor are authenticated. Unauthenticated requests are rejected.
- Saetta uses the HaloPSA API permissions you grant, through an API application you control and can revoke at any time.
Operations
- Edge DDoS protection and per-client rate limiting.
- Error monitoring with message content, credentials and request bodies excluded.
- Automated health checks on the application and database.
- Dependency updates and secret scanning on every change.
Compliance
We act as a processor for your Customer Data. A DPA is available. See our subprocessors. SOC 2 is on our roadmap.
Report a vulnerability
Email security@saetta.io (also listed in security.txt). Please give us reasonable time to fix an issue before disclosing it. We don't pursue good-faith research that respects user privacy and avoids service disruption.