Security and Trust

You are handing us
your pipeline.
We built for that.

Aijent talks to your customers and holds their details. That only works if the security underneath it is genuinely enterprise grade, so we built it that way from the first line of code, not after the first customer asked.

Audit in progress

Our SOC 2 Type I audit is underway

We are being audited by Ken & Co for SOC 2 Type I, with the Type II audit following roughly three months later. We will publish each report here the moment it is issued.

Until then we are not going to display a badge we have not earned. If you need our current control documentation for a security review, ask and we will send it.

Reviewed by the platforms you already trust

Before we could connect to these platforms, each one put us through its own security review. Every listing below is public and you can check it yourself.

Approved
HubSpot App Marketplace

Listed after HubSpot's app review, which covers scopes, data handling and security practice.

Approved
Google OAuth verification

Verified by Google for calendar access, including their review of how we request and use each scope.

Approved
Zoom App Marketplace

Published after Zoom's review, which required us to drop a sensitive scope we did not strictly need.

stripe

Payments run entirely on Stripe

Card details are entered on Stripe's own pages and never reach our systems. There is no card field anywhere in our software, so a breach of Aijency could not expose a card number. Stripe is certified to the highest PCI DSS service provider level.

ANTHROPIC

The agent runs on Anthropic's Claude

Anthropic is contractually barred from training on your conversations. They independently hold SOC 2 Type II, ISO/IEC 27001 and ISO/IEC 42001, verifiable on their own trust centre. Those are their certifications, not ours.

The four things that actually matter

In plain English, with no asterisks.

Your data is stored in Australia

Every lead, conversation and transcript is stored in Sydney, on managed PostgreSQL in the ap-southeast-2 region. Data residency you can point to on a questionnaire, not a promise to look into it.

Your conversations never train an AI model

Anthropic, who power the agent, are contractually barred from training on anything your visitors say. That is a binding agreement with us, not a setting we ticked or a policy that can quietly change.

Encrypted the whole way

Everything in transit is protected by TLS, the same encryption your bank uses. Everything sensitive at rest is encrypted with AES-256, and the keys to your CRM connection are encrypted separately again.

Walled off from every other customer

Isolation is enforced by the database itself, on every single query, not by application code remembering to ask. One customer cannot reach another customer's data even if something above it goes wrong.

What we never do

The commitments that are easiest to check and hardest to walk back.

  • We do not sell your data. Not to anyone, at any price.
  • We do not use your data for advertising.
  • We do not track visitors across other websites.
  • We do not collect browsing history or fingerprint devices.
  • We do not store IP addresses, user agents or referrers.

How we keep it that way

Security is a habit, not a launch announcement.

Customer data protection

  • Tenant isolation enforced by the database itself
  • Encryption in transit (TLS)
  • Encryption at rest (AES-256)
  • CRM tokens encrypted separately (AES-256-GCM)
  • Stored in Australia, ap-southeast-2 (Sydney)

Payments

  • Card details entered on Stripe, never on our site
  • Stripe-hosted checkout and billing portal
  • No card number ever stored, sent or logged by us
  • Stripe is a PCI DSS Level 1 service provider

Application protection

  • Static code analysis on every change merged
  • Secret scanning on every change, plus weekly
  • OAuth 2.0 with PKCE wherever supported
  • We never hold your CRM password

Infrastructure

  • Managed PostgreSQL with encryption at rest
  • Application compute pinned to the Sydney region
  • Secrets in a dedicated, access-controlled manager
  • Documented key-management policy

Monitoring and response

  • Append-only audit log, unchangeable by anyone
  • Continuous error monitoring, every environment
  • Uptime monitoring with alerting
  • Public status page

Privacy and compliance

  • Australian Privacy Act 1988
  • GDPR with Standard Contractual Clauses
  • PDPA (Singapore)
  • No AI model training on your conversations
  • Published sub-processor list

Doing a security review?

This page is the plain English version. The full technical detail, written for procurement teams and security reviewers, covers exactly what we collect, how it flows, every control we run and every company that touches your data.

Found a vulnerability?

Report it to security@aijency.ai. We acknowledge every report, we will keep you updated while we fix it, and we will never take action against anyone who reports a genuine issue in good faith.

security.txt

Live system status

Uptime and incidents are published continuously, not summarised after the fact. If we are having a bad day you will see it here before you have to ask.

View the status page

Ready to turn your website into a 24/7 sales machine?

Start Free Trial