Security
How the platform is built and operated. Specifics below are placeholders — confirm each against the real environment before launch.
See also data protection and the legal overview. To report a vulnerability, jump to reporting a vulnerability.
Summary. Least privilege by default, encrypt in transit and at rest, keep an audit trail for anything that touches customer data, and make the safe path the easy one for the people operating the system.
An AI agent adds a specific obligation: what it may read, what it may act on alone, and what it must hand to a human should be an explicit configuration, not an emergent behaviour. That boundary is set per account and logged.
Summary. Customer data is encrypted in transit between your users, your systems and ours, and encrypted at rest in our data stores.
Specifics: [Confirm and state: minimum TLS version and cipher suites, at-rest algorithm, key management and rotation, and whether customer-managed keys are offered.]
Summary. Conversation data is retained while your account is active. You can export it at any time, and deletion requests are honoured on a defined schedule that also covers backups.
Specifics: [Confirm and state: storage regions, backup frequency and retention, restore testing cadence, and the deletion SLA including backups.]
Summary. Access to production is limited to staff who need it, granted for a reason and reviewed. Customer-side, the platform supports SSO/SAML, SCIM provisioning and role-based permissions.
Specifics: [Confirm and state: MFA enforcement, privileged access review cadence, joiner/mover/leaver process, and whether customer-facing audit logs are available on which plans.]
Summary. The platform runs on managed cloud infrastructure with environments separated and changes delivered through reviewed, automated deployment.
Specifics: [Confirm and state: hosting provider and regions, tenancy model, network segmentation, vulnerability scanning and patching cadence, and the model providers in the inference path.]
Summary. The site currently presents SOC 2 Type II, GDPR and HIPAA-ready. Each of those is a different kind of claim and should be stated precisely.
Specifics: [Confirm and state: SOC 2 Type II report date, auditor, observation window, and how customers request the report under NDA. If the report is not yet issued, say "SOC 2 Type II in progress" here and in the footer badges rather than implying a completed audit.]
Summary. Two things are worth saying plainly. First, we secure the platform — we cannot secure what your team pastes into a conversation, so treat the transcript as a place customer data will end up. Second, an AI agent is only as bounded as its configuration: if it is granted an action, it can take that action.
If either of those matters to your risk model, set the authority boundary narrowly at the start and widen it once you have evidence from your own queue.
Summary. If you believe you have found a vulnerability, report it to security@aftersales.co. Include enough detail to reproduce it, and give us a reasonable window to fix it before disclosing publicly. We will not pursue legal action against good-faith research that respects user privacy and avoids service disruption.
Specifics: [Confirm and state: acknowledgement and triage timelines, scope and out-of-scope list, safe-harbour wording reviewed by counsel, whether a bounty is offered, and provision the security@ mailbox and a security.txt file.]
Last updated: September 2026 · Security contact: security@aftersales.co