Security & Compliance

Built for post-sales data you can't afford to leak

Aitelligent sits on your most sensitive customer signals — CRM records, support tickets, transcripts and revenue data. This page sets out the controls, SLAs and data protection commitments we hold ourselves to.

Security architecture

Encryption everywhere

  • TLS 1.2+ for all data in transit, HSTS enforced on all public endpoints
  • AES-256 encryption at rest for databases, object storage and backups
  • Secrets held in a managed secret store — never in source control or client bundles

Tenant isolation

  • Row-Level Security enforced on every customer-facing table
  • Every query is scoped to the authenticated user's company and role
  • Privileged service credentials are used only in verified server-side paths

Access control

  • Role-based permissions stored server-side and validated on every request
  • OAuth-based integration connections; per-tenant credentials, never shared keys
  • Least-privilege internal access, reviewed quarterly, revoked within 24h of offboarding

Auditability

  • Immutable audit trails for sync runs, CSQL handoffs and webhook deliveries
  • Full email send/delivery log with failure reasons and retry state
  • Security and access logs retained for 12 months

Secure development

  • Automated dependency and vulnerability scanning on every change
  • Signed webhooks with HMAC verification and replay protection
  • Input validation on every server function; no client-only trust boundaries

Resilience

  • Daily encrypted backups with point-in-time recovery
  • Exponential-backoff retries with dead-letter queues for outbound jobs
  • Documented business continuity and disaster recovery procedures

Service level agreements

Availability, response and data-handling commitments. Enterprise contracts can tighten these targets.

CommitmentTarget
Uptime commitment99.9% monthly
P1 — service down1 hour response
P2 — major degradation4 business hours
P3 — minor issue / question1 business day
Breach notificationWithin 24 hours
Data subject request supportWithin 5 business days
Data deletion after termination30 days on request

Data protection & GDPR

  • Signed Data Processing Agreement (DPA) available to all paying customers, incorporating UK GDPR Article 28 terms.
  • Records of Processing Activities (ROPA) maintained and reviewed annually.
  • Data Protection Impact Assessments (DPIA) completed for AI scoring, call-transcript processing and CRM handoff flows.
  • Data minimisation by design — we ingest only the fields required to score health and trigger playbooks.
  • Purpose limitation — customer content is never used to train foundation models, and model providers are contractually bound to exclude our traffic from training.
  • Sub-processor register maintained with written data-processing terms; customers are notified before any new sub-processor is engaged.
  • International transfers governed by UK adequacy regulations, EU Standard Contractual Clauses and the UK International Data Transfer Addendum, backed by transfer risk assessments.
  • Named privacy contact and documented data subject rights process (access, rectification, erasure, restriction, portability, objection).
  • Retention schedules enforced per data category, with automated expiry of logs and AI prompt history.
  • Annual staff security and data protection training, with confidentiality obligations in all employment and contractor agreements.

Frameworks we align to

UK GDPR & Data Protection Act 2018Adhered to
EU GDPR (Regulation 2016/679)Adhered to
SOC 2 Type II control alignmentControls mapped; audit in progress
ISO/IEC 27001 control alignmentControls mapped
PCI-DSS (via payment processor)Out of scope — no card data stored
OWASP ASVS secure coding practicesApplied in development

Incident response

  1. 1. Detect — automated alerting on anomalies, failures and access events.
  2. 2. Triage — severity assigned within 1 hour, incident owner named.
  3. 3. Contain & Eradicate — isolate, patch, rotate credentials.
  4. 4. Notify — affected controllers within 24 hours of confirmation.
  5. 5. Review — written post-incident report and corrective actions.

Report a suspected vulnerability or incident to info@aitelligent.co — we acknowledge within one business day and do not pursue good-faith researchers.

Running a security or procurement review?

We'll share our DPA, sub-processor register, security questionnaire responses and architecture overview.