Skip to content
Sawadoo

Security and privacy

A summary of how Sawadoo is built to keep your work private. It describes the product as it works today and is not a certification or a contract.

Each account is kept separate

Every record belongs to one account. The database itself enforces that separation with row-level security, so a request made for one account cannot read or change another account's data, even if the application code were to ask for it.

Permissions are checked on the server, every time

The web app, the API, the MCP server, background jobs and the AI assistant all go through the same permission checks. Clients see only items marked visible to clients, in the tools you have opened to them, within their permission profile. Hidden items are left out of lists, search, counts, notifications and API responses.

Sign-in

Email addresses are verified before an account can be used. People can sign in with a password, a one-time link sent by email, or Google where it is enabled, and can add two-factor authentication with an authenticator app. An account can require two-factor authentication for everyone.

Files, transport and backups

Connections use HTTPS. Uploaded files are stored privately and are downloaded through short-lived links issued only to people allowed to see them. In production, file storage and the database are encrypted at rest, and the database is backed up daily.

A record of what happened

Every change to an item is recorded with who made it, and shown in the project's activity. Changes to people, permissions and billing are also written to an audit log. Deleted items stay in the trash for 30 days before they are removed for good.

AI features

The assistant and agents act with the permissions of the person or project they work for and can never see more than that. Changes proposed by the assistant are made only after a person confirms them. An account can switch the assistant and agents off. Questions are sent to the AI provider only to produce the answer.

API and integrations

API access uses OAuth 2 or personal access tokens that can be revoked at any time. Webhook deliveries are signed, so the receiver can verify them, and may only be sent to public HTTPS addresses. Requests are rate limited per token.

Your data stays yours

An account owner can export the account's data and files, and can close the account. The app carries no advertising and no third-party tracking scripts.

Report a security problem

If you believe you have found a vulnerability, write to support@sawadoo.com. Please give us a reasonable time to fix it before making it public.