Security & Compliance
Built for post-sales data you can't afford to leak
Aitelligent sits on your most sensitive customer signals — CRM records, support tickets, transcripts and revenue data. This page sets out the controls, SLAs and data protection commitments we hold ourselves to.
Security architecture
Encryption everywhere
- TLS 1.2+ for all data in transit, HSTS enforced on all public endpoints
- AES-256 encryption at rest for databases, object storage and backups
- Secrets held in a managed secret store — never in source control or client bundles
Tenant isolation
- Row-Level Security enforced on every customer-facing table
- Every query is scoped to the authenticated user's company and role
- Privileged service credentials are used only in verified server-side paths
Access control
- Role-based permissions stored server-side and validated on every request
- OAuth-based integration connections; per-tenant credentials, never shared keys
- Least-privilege internal access, reviewed quarterly, revoked within 24h of offboarding
Auditability
- Immutable audit trails for sync runs, CSQL handoffs and webhook deliveries
- Full email send/delivery log with failure reasons and retry state
- Security and access logs retained for 12 months
Secure development
- Automated dependency and vulnerability scanning on every change
- Signed webhooks with HMAC verification and replay protection
- Input validation on every server function; no client-only trust boundaries
Resilience
- Daily encrypted backups with point-in-time recovery
- Exponential-backoff retries with dead-letter queues for outbound jobs
- Documented business continuity and disaster recovery procedures
Service level agreements
Availability, response and data-handling commitments. Enterprise contracts can tighten these targets.
| Commitment | Target | Detail |
|---|---|---|
| Uptime commitment | 99.9% monthly | Enterprise plans, measured on the core Dashboard and API |
| P1 — service down | 1 hour response | Continuous updates until mitigated |
| P2 — major degradation | 4 business hours | Workaround targeted within 1 business day |
| P3 — minor issue / question | 1 business day | Resolution in the next release cycle |
| Breach notification | Within 24 hours | To affected controllers, ahead of the 72-hour GDPR duty |
| Data subject request support | Within 5 business days | Assistance to you as controller |
| Data deletion after termination | 30 days on request | 90 days maximum; backups age out within 35 further days |
Data protection & GDPR
- Signed Data Processing Agreement (DPA) available to all paying customers, incorporating UK GDPR Article 28 terms.
- Records of Processing Activities (ROPA) maintained and reviewed annually.
- Data Protection Impact Assessments (DPIA) completed for AI scoring, call-transcript processing and CRM handoff flows.
- Data minimisation by design — we ingest only the fields required to score health and trigger playbooks.
- Purpose limitation — customer content is never used to train foundation models, and model providers are contractually bound to exclude our traffic from training.
- Sub-processor register maintained with written data-processing terms; customers are notified before any new sub-processor is engaged.
- International transfers governed by UK adequacy regulations, EU Standard Contractual Clauses and the UK International Data Transfer Addendum, backed by transfer risk assessments.
- Named privacy contact and documented data subject rights process (access, rectification, erasure, restriction, portability, objection).
- Retention schedules enforced per data category, with automated expiry of logs and AI prompt history.
- Annual staff security and data protection training, with confidentiality obligations in all employment and contractor agreements.
Frameworks we align to
UK GDPR & Data Protection Act 2018Adhered to
EU GDPR (Regulation 2016/679)Adhered to
SOC 2 Type II control alignmentControls mapped; audit in progress
ISO/IEC 27001 control alignmentControls mapped
PCI-DSS (via payment processor)Out of scope — no card data stored
OWASP ASVS secure coding practicesApplied in development
Incident response
- 1. Detect — automated alerting on anomalies, failures and access events.
- 2. Triage — severity assigned within 1 hour, incident owner named.
- 3. Contain & Eradicate — isolate, patch, rotate credentials.
- 4. Notify — affected controllers within 24 hours of confirmation.
- 5. Review — written post-incident report and corrective actions.
Report a suspected vulnerability or incident to info@aitelligent.co — we acknowledge within one business day and do not pursue good-faith researchers.
Running a security or procurement review?
We'll share our DPA, sub-processor register, security questionnaire responses and architecture overview.