SOC 2 · ISO 27001 · GDPR

Sovereign communications. Audited and accountable.

Built for organisations that need GDPR compliance, audit trails, and self-host options — without giving up end-to-end encryption.

Organisations + RBAC

Guest → Member → Moderator → Admin → Owner. Permissions middleware enforces every action server-side.

Audit logging

30 audit-action types. SOC 2 + ISO 27001 mapped. Retention configurable per plan.

GDPR data control

One-click data export. Right-to-erasure on demand. Subprocessor list public.

Webhooks

HMAC-SHA256 signed. 10 event types. Exponential-backoff retry, auto-disable after persistent failure.

Rate limiting

Token bucket per endpoint. Multipliers for authenticated and enterprise tiers.

Self-host on Enterprise tier

Run the entire Saj Link stack inside your VPC. Federation across self-hosted instances supported.

Compliance posture

GDPR · SOC 2 (Type II in flight) · ISO 27001 alignment. Annual third-party penetration test.

2FA + session management

TOTP. Active session list. Remote logout. Per-channel privacy overrides.

Talk to us.

We'll walk you through deployment options, compliance posture, and pricing.