Security

How Sissel protects your data.

These are the controls in the product today. Sissel is still in beta, so we do not claim certifications or compliance work that has not been independently verified.

Production details

Hosting region: Finland (primary hosting); France (encrypted backups and transactional email) · Security reports: privacy@sissel.app · Reviewed 9 August 2026.

Your workspace stays separate

Sissel scopes application data to your organisation. Database row-level security adds another boundary underneath the application.

Secrets stay secret

Connector credentials and private keys are encrypted at rest. Once you save a secret, Sissel does not display it again.

Retries do not create duplicates

Every conversion uses a stable event ID. You can inspect a failed attempt and retry it without quietly sending the result twice.

Browser data comes from approved sites

Browser events need both a site-specific public key and an allowed origin. A public key alone cannot send data from another domain.

Important changes leave a trail

Sissel records consequential configuration and delivery changes so your team can review what happened later.

What we encrypt

Sissel encrypts connector credentials, person identifiers, pending collector data, certificate private keys and Zapier target URLs at rest with AES-256-GCM. Identifier lookups use keyed HMACs, so a copy of the database is not enough to test possible email addresses or phone numbers. Key custody and rotation are agreed before production use.

Backups and incidents

Sissel includes procedures for encrypted backups and verified restores. Before production use, we agree who owns backups and incidents, the recovery targets, the notification route, the latest restore evidence and the relevant subprocessors.