Trust

Security at SisiDesk

A workspace holds everything a professional is working on. These are the controls that protect it, and the limits we are honest about.

Tenant isolation

Every workspace runs in its own hardware-virtualised instance with a dedicated persistent volume and its own network namespace. There is no shared runtime between customers and no shared filesystem.

Encryption

Session transport is encrypted end to end. Volumes and control-plane data are encrypted at rest with managed keys, rotated on a fixed schedule.

Tenant-bound intelligence

OCR, embeddings and vector search execute inside your workspace instance. The control plane has no read path into workspace storage, so it cannot index or search your documents.

Least-privilege access

Production access is role-scoped, requires multi-factor authentication, and is logged. No engineer holds standing access to customer workspaces.

Data residency

You pick the region for each workspace, and its data stays there. Control-plane metadata — workspace names, session minutes, invoices — may be processed in another region, and we disclose that in the privacy policy.

Access to your workspace

Support staff cannot enter a running workspace on their own initiative. An access grant must be created by you, is bounded to a duration you set, expires automatically, and is written to your audit log where you can review it after the fact.

Audit and visibility

  • Every security-relevant action — sign-in, device trust change, workspace creation, handoff, role change — writes an audit event scoped to your account.
  • Session cost and duration are visible in the cost ledger as they accrue, not only on the invoice.
  • Trusted devices can be listed and revoked at any time from the devices page.

Business continuity

  • Volume snapshots are taken on a rolling schedule and stored in the same region as the workspace.
  • Volumes are retained for 30 days after deletion or lapse, then permanently destroyed.
  • Volumes export as standard disk images, so leaving does not require our cooperation.

Incident response

We triage suspected incidents on a 24-hour clock and notify affected account owners without undue delay, with the facts we have confirmed rather than a holding statement. Post-incident reviews are shared with affected customers.

Reporting a vulnerability

Send findings to hello@sisidesk.com with the subject line "Security". We acknowledge within two business days, will not pursue good-faith researchers, and credit reporters who want it. Please do not test against another customer's workspace.

What we do not claim yet

SisiDesk is in beta. We are not currently SOC 2 or ISO 27001 certified, and we will not imply otherwise while an audit is incomplete. Formal audit is scheduled to begin once general availability opens; procurement teams that need a security questionnaire completed in the meantime can write to deals@sisidesk.com.