Trust & Security
Security you can hand your customers
When a customer calls, chats, or emails your business, that conversation can contain sensitive information. This page explains, in plain language, how 247Aisupports protects that data — so you can adopt AI support with confidence. Last updated: July 1, 2026.
1. How we handle your data
You own your data. Knowledge-base content, agent configuration, and the conversations between your AI agents and your customers belong to you — we process them only to run the service on your behalf.
All AI processing happens server-side. Your website visitors interact with a thin client widget; the underlying AI keys, prompts, and configuration are never exposed to the browser. We do not sell, rent, or trade your data.
2. Encryption
- In transit: every connection to the platform — dashboard, widget, voice, and API — is secured with HTTPS/TLS.
- At rest: integration secrets you store (for example, credentials for systems your agent connects to) are encrypted with AES-256-GCM before they are written to the database.
- Passwords: account passwords are hashed with bcrypt and are never stored or logged in plaintext.
3. Our AI subprocessor
We use a leading enterprise AI provider to generate AI responses across voice, chat, and email. Conversation content is sent to our AI provider's API server-side, solely to produce a reply to your customer.
We do not train AI models on your data, and your data is not used to train third-party AI models. Model names, system prompts, and internal configuration are never exposed to end-users or in any client-facing surface.
4. Per-tenant data isolation
247Aisupports is multi-tenant by design. Every business account (tenant) is logically isolated: each record carries a tenant identifier, and every data access is scoped to the authenticated tenant derived from the session — never from anything the browser can supply. One customer can never see, query, or reach another customer's data.
5. Access controls
- Dashboard access is protected by JWT-based authentication with bcrypt-hashed credentials.
- Two-factor authentication (TOTP / authenticator app) is available for account owners.
- Sessions can be revoked, so you can sign out other devices if a credential is ever exposed.
- Platform administration is separated from tenant accounts, with an audit log of administrative actions and the ability to suspend or lock an account (a kill-switch) if abuse is detected.
6. Abuse & misuse protection
- Rate limiting protects the platform and your plan from spikes and automated abuse.
- All user input is sanitized, and we run prompt-injection detection to defend the AI against manipulation attempts.
- Per-plan concurrency and usage caps act as an additional guard against runaway usage.
7. Data retention & deletion
Conversation data is retained while your account is active so your agents can reference it and you can review transcripts. You can request deletion of your data at any time by contacting us. When an account is terminated, associated data is deleted within 30 days. Full details are in our Privacy Policy.
8. Subprocessors
We rely on a small set of trusted providers to deliver the service:
- Enterprise AI provider — AI response generation (LLM inference) for voice, chat, and email.
- Cloud infrastructure provider — application hosting and infrastructure.
A more detailed list, including data categories, is available in our Data Processing Agreement.
9. Your compliance rights
We operate in accordance with the Philippines Data Privacy Act of 2012 (Republic Act No. 10173). As a data subject you can access, correct, or request erasure of your personal data, object to processing, request portability, and lodge a complaint with the National Privacy Commission. See the Privacy Policy for how to exercise these rights.
10. What we are still working on — honestly
We believe in telling you exactly where we stand rather than implying certifications we do not yet hold:
- We are not currently SOC 2 or ISO 27001 certified. A formal security program and third-party attestation are on our roadmap.
- We are not HIPAA-certified and do not currently offer a signed BAA. If you handle regulated health data, talk to us first about whether the platform fits your requirements.
- A formal, countersigned Data Processing Agreement is in progress; a reviewable DPA template is available today.
11. Report a security concern
If you believe you have found a vulnerability or have a security question, please email [email protected]. We take reports seriously and will respond promptly.
