Security
You’re trusting Sieve with your customers. Here is exactly how we protect them.
Data
- Names, phones, emails, national IDs, BVNs and dates of birth are encrypted with AES-256-GCM.
- Phones, emails, IDs (including BVNs), payout accounts and devices are also indexed with keyed HMAC-SHA256, so “is this phone shared by another customer?” is answered without decrypting anything.
- Test and live data are fully separated; a test key can never read or influence live data.
Access
- Passwords use Argon2id. Accounts lock after repeated failures; errors never reveal whether an email exists.
- Two-factor authentication (TOTP) is required before live keys can be created.
- Sessions are opaque tokens in httpOnly, SameSite=Strict cookies, with CSRF protection on every change and idle timeouts.
- Roles: owner, admin, analyst, viewer. Viewers see personal data masked.
- API keys are shown once and stored as SHA-256 fingerprints; they can be revoked instantly and are rate-limited.
Integrity
- Every sensitive action is written to an append-only, hash-chained audit log per workspace. “Verify chain” re-computes every hash.
- Webhooks are signed with replay protection; outbound URLs must be public https (no internal network access). On-premise installs invert this: with
SIEVE_EGRESS=private, webhooks may only reach your internal network. - Strict input validation on every endpoint; errors never leak internals.