SOC 2 · ISO 27001 · GDPR

Sovereign communications. Audit trails. Accountability built in.

Built for organisations that need GDPR compliance, audit trails, and self-host options — without giving up end-to-end encryption.

Organisations + RBAC

Guest → Member → Moderator → Admin → Owner. Permissions middleware enforces every action server-side.

Audit logging

30 audit-action types. SOC 2 + ISO 27001 mapped. Retention configurable per plan.

GDPR data control

One-click data export. Right-to-erasure on demand. Subprocessor list public.

Webhooks

HMAC-SHA256 signed. 10 event types. Reliable delivery with backoff and circuit-breaker.

Rate limiting

Per-endpoint limits with tiered multipliers for authenticated and enterprise tiers.

Self-host on Enterprise tier

Run the entire Saj Link stack inside your VPC. Federation across self-hosted instances supported.

Compliance posture

GDPR · SOC 2 Type II (in progress) · ISO 27001 alignment · FedRAMP pathway. Third-party penetration testing (planned).

2FA + session management

TOTP. Active session list. Remote logout. Per-channel privacy overrides.

Talk to us.

Deployment options, compliance posture, and pricing — on a call.