Security at Savannah
We take the security of data processed through Savannah seriously. Below are the technical and organizational measures we maintain to protect your Content, Generated Output, and account information.
All data in transit is encrypted using TLS 1.2 or higher
Passwords are hashed using bcrypt and never stored in plain text
Authentication uses JWT tokens with short expiry and secure refresh flows
Access to production systems is restricted to authorized personnel with multi-factor authentication (MFA)
Regular security reviews and penetration testing
Automated monitoring and alerting for anomalous activity
Strict data isolation between customers — no customer's data is ever shared with another
In the event of a breach affecting your rights, we notify affected users and relevant authorities as required by law, including within 72 hours for GDPR-applicable incidents
For the list of third parties that process data on our behalf, see our subprocessors.