Security & Trust

Enterprise-grade security, by design.

A2CX runs the most sensitive part of your business — every customer conversation — so security isn't a feature, it's the foundation. Here's exactly how we protect your data, and the standards we're built to meet.

Tenant isolation, verified on every deploy Encrypted in transit & at rest Fully audited On-prem Sovereign option

How we protect your data

Strict tenant isolation

Every record is scoped to your tenant. No customer can ever see another's data — and we prove it: an automated cross-tenant isolation test runs on every single deploy and blocks the release if a single record could leak.

Encryption everywhere

All traffic is encrypted in transit with TLS. Sensitive data and credentials are encrypted at rest. Secrets are stored encrypted, never in plain text.

Role-based access & step-up auth

Granular roles (admin, supervisor, WFM, agent, executive) gate every surface. The most sensitive areas — like your AI brain — require step-up re-authentication even for logged-in admins.

Full audit logging

Every meaningful action — logins, configuration changes, data access — is recorded in an immutable audit log, scoped to your tenant and available for review.

Your data never trains shared AI

Your knowledge and conversations power your private brain (NOUS) only. They are never pooled with other customers and never used to train shared or third-party foundation models.

Reliability & recovery

Automated backups, a database health pre-flight check before every release, and a tested rollback path keep your data safe and available.

Standards & compliance

A2CX is engineered to meet international data-protection and security frameworks. We are transparent about what is certified versus in progress — and we will never claim a certification we don't hold.

Standard / regulationStatusWhat it means for you
GDPR (EU)SupportedDPA available, data-subject rights (access, deletion, portability) supported, EU data residency / on-prem available.
CCPA / CPRA (US)SupportedConsumer data rights and opt-out honored.
LGPD (Brazil)SupportedAligned with Brazil's data-protection law for LatAm deployments.
LFPDPPP (Mexico)SupportedBuilt-in privacy notices (avisos), consent capture and acceptance tracking.
SOC 2In progressControls aligned with SOC 2 Trust Services Criteria; formal Type II audit on the roadmap.
ISO/IEC 27001In progressInformation-security management aligned to ISO 27001; certification on the roadmap.
HIPAA (US health)Via SovereignHIPAA-ready architecture; deploy on-premise/air-gapped for PHI, with a BAA on Enterprise.
PCI DSSSupportedA2CX does not store full card data; payments are handled by PCI-compliant processors.
Transparency note: "Supported" means the capability is live in the product today. "In progress" means our controls are aligned with the framework and formal certification is underway — we'll share current status and evidence under NDA. Request our security documentation →

For banking, government & healthcare

A2CX Sovereign — your data never leaves your walls

For the most regulated industries, A2CX deploys entirely inside your own infrastructure — on-premise or fully air-gapped. The AI brain, the data, and every conversation stay within your environment, under your control, meeting data-residency and sovereignty requirements that the cloud alone can't. You get the full A2CX platform with none of the data leaving your perimeter.

Frequently asked

Is my data isolated from other A2CX customers?

Completely. Every record is scoped to your tenant, and an automated cross-tenant isolation test runs on every deploy and blocks the release if any data could leak between tenants. Isolation isn't a promise — it's continuously verified.

Do you use my conversations to train AI?

No. Your data trains only your own private brain (NOUS), scoped to your tenant. It is never pooled with other customers or used to train shared/third-party foundation models.

Are you SOC 2 / ISO 27001 certified?

Our controls are aligned with both frameworks and formal certification is on our roadmap. We don't claim certifications we don't hold — request our current security documentation for exact status.

Can we run A2CX on our own servers?

Yes — the Sovereign option deploys A2CX on-premise or air-gapped, so sensitive data never leaves your environment. Ideal for banking, government and healthcare.

Can we sign a DPA / get a security questionnaire completed?

Yes. A DPA is available and we'll complete your security questionnaire. Use "Request security documentation" below to start.

Talk to us about your security requirements

Request our security documentation, a DPA, or a Sovereign on-prem walkthrough for your team.

Back to A2CX