Security at SA Digital Labs.
How we protect client projects, and where we stand on formal standards.
Last updated: October 4, 2026
How we work
- Your data is used only to do your project. We keep it private, and we sign an NDA on request.
- Only the people who need your data can reach it, and anyone who helps us has the same duty of confidentiality.
- We use made-up or anonymised data for development and testing wherever possible.
- For projects with personal data we sign a data processing agreement, and we agree the safeguards for the project in writing.
- If something goes wrong, we tell you quickly and help you deal with it. When the project ends, we hand your data back or delete it.
More detail is in our Privacy Policy.
Where we stand on formal standards
We want to be straightforward about this, because clients in regulated industries ask.
- SOC 2: we do not currently have a SOC 2 report.
- HITRUST: we do not currently hold a HITRUST certification.
- HIPAA: there is no official "HIPAA certification".
Our own policies are written to follow the structure of these standards, so we can meet them when a client needs it. We will not describe ourselves as compliant or certified until that is true and independently confirmed. If your project needs a specific standard, tell us before we start and we will say honestly whether we can meet it.
Reporting a security concern
If you think you have found a security problem with this website, please email contact@sadigitallabs.com with the subject "Security report" and enough detail for us to reproduce it. Please do not access other people's data or disrupt the service while testing. We will look at every report.