A2CX runs the most sensitive part of your business — every customer conversation — so security isn't a feature, it's the foundation. Here's exactly how we protect your data, and the standards we're built to meet.
Every record is scoped to your tenant. No customer can ever see another's data — and we prove it: an automated cross-tenant isolation test runs on every single deploy and blocks the release if a single record could leak.
All traffic is encrypted in transit with TLS. Sensitive data and credentials are encrypted at rest. Secrets are stored encrypted, never in plain text.
Granular roles (admin, supervisor, WFM, agent, executive) gate every surface. The most sensitive areas — like your AI brain — require step-up re-authentication even for logged-in admins.
Every meaningful action — logins, configuration changes, data access — is recorded in an immutable audit log, scoped to your tenant and available for review.
Your knowledge and conversations power your private brain (NOUS) only. They are never pooled with other customers and never used to train shared or third-party foundation models.
Automated backups, a database health pre-flight check before every release, and a tested rollback path keep your data safe and available.
A2CX is engineered to meet international data-protection and security frameworks. We are transparent about what is certified versus in progress — and we will never claim a certification we don't hold.
| Standard / regulation | Status | What it means for you |
|---|---|---|
| GDPR (EU) | Supported | DPA available, data-subject rights (access, deletion, portability) supported, EU data residency / on-prem available. |
| CCPA / CPRA (US) | Supported | Consumer data rights and opt-out honored. |
| LGPD (Brazil) | Supported | Aligned with Brazil's data-protection law for LatAm deployments. |
| LFPDPPP (Mexico) | Supported | Built-in privacy notices (avisos), consent capture and acceptance tracking. |
| SOC 2 | In progress | Controls aligned with SOC 2 Trust Services Criteria; formal Type II audit on the roadmap. |
| ISO/IEC 27001 | In progress | Information-security management aligned to ISO 27001; certification on the roadmap. |
| HIPAA (US health) | Via Sovereign | HIPAA-ready architecture; deploy on-premise/air-gapped for PHI, with a BAA on Enterprise. |
| PCI DSS | Supported | A2CX does not store full card data; payments are handled by PCI-compliant processors. |
For the most regulated industries, A2CX deploys entirely inside your own infrastructure — on-premise or fully air-gapped. The AI brain, the data, and every conversation stay within your environment, under your control, meeting data-residency and sovereignty requirements that the cloud alone can't. You get the full A2CX platform with none of the data leaving your perimeter.
Completely. Every record is scoped to your tenant, and an automated cross-tenant isolation test runs on every deploy and blocks the release if any data could leak between tenants. Isolation isn't a promise — it's continuously verified.
No. Your data trains only your own private brain (NOUS), scoped to your tenant. It is never pooled with other customers or used to train shared/third-party foundation models.
Our controls are aligned with both frameworks and formal certification is on our roadmap. We don't claim certifications we don't hold — request our current security documentation for exact status.
Yes — the Sovereign option deploys A2CX on-premise or air-gapped, so sensitive data never leaves your environment. Ideal for banking, government and healthcare.
Yes. A DPA is available and we'll complete your security questionnaire. Use "Request security documentation" below to start.
Request our security documentation, a DPA, or a Sovereign on-prem walkthrough for your team.