Security Overview
Last updated: 1 May 2026
A summary of how we protect your account, your business content, and your visitors' conversations.
1. Encryption
TLS 1.3 in transit (HSTS enforced). AES-256 at rest for all stored data. Key rotation every 90 days. Backup encryption with separate keys.
2. Access control
Sign-in via SSO (Google, Microsoft) recommended. Two-step sign-in available. Session tokens expire after 12 hours of inactivity. Internal staff access is least-privilege, audited, and requires JIT approval for production data.
3. Bulk export blocking
Bulk download of full content library or full conversation history is blocked at platform level. Granular exports require admin confirmation. Activity log records every export.
4. Tenant data isolation
Each customer's content lives in its own tenant. Database-level Row Level Security and per-tenant vector retrieval make other customers' data structurally invisible — the assistant can only ever read your knowledge base. You can pause the assistant or wipe your data in one click.
5. No model training
Your data is never used to train AI models — for us or any other customer. We have technical and contractual controls preventing this.
6. Network security
Web Application Firewall (WAF), DDoS protection, intrusion detection, automated vulnerability scanning. Production network is isolated from staging.
7. Audit & compliance
Independent third-party audits (such as SOC 2) and penetration testing are on our security roadmap. We currently run internal security reviews every 6 months and can share a written summary of our controls on request.
8. Incident response
Documented incident response playbook. 24-hour notification target for personal data breaches. Post-incident report shared with affected customers.
9. Vulnerability disclosure
Responsible disclosure welcome at security@engagelayer.io. We do not pursue legal action against good-faith researchers. Bounty program details on request.
The English version of these documents is the legally authoritative reference.