# Security Overview and Access to the Detailed TOMs Last updated: 2026-08-01 This public overview describes the principles of savien's technical and organisational measures under Art. 32 GDPR. It supports an initial security review without disclosing internal configurations or other information that could facilitate attacks. ## 1. Security Principles - Access to accounts and company data is authenticated and restricted by role. - Permissions follow the principle of least privilege. - Data transmitted between the browser, application and connected services is protected in transit. - Application- and database-level controls separate tenant and storage access. - Security-relevant changes and events are logged to an extent appropriate for their purpose. - Recovery, update and response processes are reviewed regularly and adapted after material changes. - Service providers that may access personal data are assessed contractually and on a risk basis. ## 2. Measure Categories The detailed TOMs address physical and logical access, authorisation, transmission, input, availability and separation controls, as well as processes for permissions, vulnerabilities, security incidents, backups and recovery. Measures are selected and developed taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to data subjects. ## 3. Details Not Published The public overview does not disclose keys or secrets, internal identifiers, network or firewall rules, detailed storage or backup paths, alert thresholds, administrative access information or complete incident playbooks. ## 4. Access Before Accepting the DPA Authorised prospective and existing customers may inspect the detailed TOMs applicable to the intended agreement before accepting the DPA: 1. Email security@savien.io with the subject “TOM access”. 2. State the organisation, business email address, the requester's role and the relationship to the intended or existing agreement. 3. savien verifies the business identity and authority of the requester. 4. After successful verification, savien provides a versioned, read-only copy through a protected access channel. An existing user account or an already executed DPA is not required. 5. Questions and documented objections may be submitted to security@savien.io before acceptance. The version incorporated into the agreement is identified by document ID, version and content hash. ## 5. Related Documents - [Data Processing Agreement](/en/dpa) - [Subprocessor List](/en/subprocessors) - Security contact: security@savien.io