SavvySavvy← Back to site

Security

Last updated 24 August 2026

Credit information is among the most sensitive data there is, and we built Savvy around that fact. This page explains exactly how your data is protected. It complements our Privacy Policy and Data Residency statement.

1. Six commitments we don't compromise on

  • AES-256 encryption. Your data is encrypted at rest with AES-256 and in transit over TLS 1.2+. Nothing sensitive is ever stored or logged in plain text.
  • Your report file is never stored. The document you upload is held in memory only for as long as it takes to read it. It is never written to disk, never logged, and never retained — so there is no stored file to leak.
  • PII-stripping middleware. Before any report is analysed, a dedicated layer removes personal identifiers — your name, Emirates ID, account numbers. The analysis engine never sees who you are.
  • No bank linking. Savvy works only from the report you choose to upload. We never connect to your bank accounts, never hold your banking credentials, and can never move money.
  • You stay in control. It's your data. You decide what to upload, you can export it, and you can delete your account and everything in it at any time, permanently.
  • Least-privilege access. Strict internal access controls mean no one at Savvy can browse your data. Access is role-based, logged, and limited to what's needed to run the service.

2. We never touch the credit bureau

Savvy is upload-only by design. We have no automated or programmatic connection to the Al Etihad Credit Bureau (AECB) — no credential-based login, no automation, no scraping. You obtain your own report from the bureau and choose to share it with us. This is a deliberate architectural boundary, not a limitation we intend to remove.

3. Regulatory context

Savvy is a technology product, not a financial service. We are not licensed or regulated by the Central Bank of the UAE (CBUAE), the Al Etihad Credit Bureau, the ADGM Financial Services Regulatory Authority, or the DFSA, and we do not require such a licence: we do not hold or move money, extend credit, or access payment accounts.

Our engineering and data practices are designed with reference to:

  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, which governs how we handle your information.
  • CBUAE and ADGM FSRA published guidance for financial-technology providers, which we use as a benchmark for conduct and data expectations.
  • AECB data-use rules — your report is read and decoded for you, and never resold.
  • Global security standards — ISO 27001 principles, OWASP secure-development guidance, and modern encryption standards.

4. What happens to your report

  • Uploaded over an encrypted connection. Your report travels over TLS and is held in memory. It is never written anywhere in plain text — or at all.
  • Stripped and decoded. Personal identifiers are removed, then the report is decoded. The engine works on the numbers, not on your identity.
  • Yours to keep or erase. The extracted results stay encrypted and private to you. Export them whenever you like, or delete your account and all data permanently, on your terms.

5. Reporting a vulnerability

If you believe you have found a security issue, email hello@besavvysure.com and we will respond promptly. We would rather over-explain than leave you wondering.

Savvy provides credit information and educational tools. It is not a credit bureau, a lender, or a financial adviser. We work only from the official credit report you choose to share, we never connect to your bank accounts, and we never sell your data.

Tropika Labs F.Z.E, Office B.C. 1307823, C1 Building, Ajman Free Zone, P.O. Box 932, Ajman, UAE

Written in plain language so it is actually readable. It sets out our binding commitments to you, but it is a summary of how we operate rather than legal advice to you — for advice on your own situation, speak to a qualified professional.