Looking for our Chatbot solution?Go to Expertise Live

Security and Trust

Security engineered for AI that can act

Expertise protects customer conversations, connected business data, and agent actions with tenant isolation, scoped access, sandboxed execution, policy screening, and human approval controls.

Our controls span the full system—not just the model—from identity and infrastructure to integrations, runtime isolation, authorization, and auditability.

Independent assurance and customer evidence
Review the evidence

SOC 2 Type II

Independent assessment of the design and operating effectiveness of our controls.

SOC 3

A public assurance report covering our security, availability, and confidentiality controls.

Independent penetration test

Third-party testing and remediation tracking help validate our security posture.

DPA available

Contractual data-protection commitments and supporting documentation for customer reviews.

Product security

The right controls for each AI experience

Expertise and Expertise Live share a secure platform foundation, but their threat models are different. We apply controls according to what each product can see and do.

Expertise Live

Protected customer conversations

Expertise Live engages public website visitors and must treat every message, file, and retrieved source as untrusted input.

  • Tenant-scoped knowledge

    Each chatbot's knowledge lives in its own isolated vector namespace, keeping retrieval scoped per customer and per agent.

  • Untrusted-input boundaries

    Visitor messages, retrieved content, and conversation history remain distinct from system instructions and customer configuration.

  • Application-layer defenses

    Input validation, rate limiting, spam controls, and SSRF protections reduce common abuse paths, with output sanitization and embed restrictions applied in supported clients.

  • Grounded responses

    Retrieval and response controls help the AI stay within authorized customer knowledge and configured behavior.

  • Verified integrations

    Webhook signature checks, verification tokens, and event deduplication protect supported channels where the provider offers them.

Expertise

Contained agent execution

The Expertise assistant can use tools and connected systems, so its controls extend beyond the model into the runtime and authorization layers.

  • Skill-bundle screening

    Instructions, metadata, accessory files, and declared connectors are screened before a skill bundle enters the runtime.

  • User-scoped sandboxes

    Agent execution runs in isolated, user-scoped microVM sandboxes with runtime, filesystem, and process boundaries.

  • Backend-held credentials

    Connector and integration credentials stay in the control plane and out of prompts; the sandbox receives only the scoped credentials a session needs.

  • Deterministic tool authorization

    Server-side connector, method, and route policies constrain what the agent can invoke independently of model output.

  • Human approval for consequential actions

    Classified writes can require human approval before they run; unknown write behavior fails closed to review.

AI defense in depth

The model does not define its own security boundaries

Prompt safeguards are useful, but they are only one layer. Expertise combines model-level defenses with isolation, credential boundaries, deterministic authorization, and audit controls outside the model.

Shared

Treat external content as untrusted

User input, retrieved material, and integration data are separated from higher-priority instructions.

Expertise

Screen what enters the runtime

Skill bundles are checked for embedded secrets, exfiltration behavior, instruction subversion, and disallowed content.

Expertise

Contain execution

User-scoped sandboxes isolate processes, files, workspaces, and agent state across runtime boundaries.

Shared

Keep credentials out of prompts

Connector OAuth credentials are encrypted or stored in managed secret services and stay out of prompts and model context.

Expertise

Authorize actions outside the model

Server policies, scoped tokens, quotas, approvals, and audit events constrain consequential tool use.

A malicious prompt cannot connect a new system or pull connector credentials into its context — those boundaries are enforced by the server, outside the model.

Platform foundation

Security across the full system

Shared controls protect identities, customer data, applications, infrastructure, and operational access across both products.

Tenant isolation

Customer resources are partitioned by tenant-scoped identifiers and isolated data namespaces, with server-side access checks on authenticated routes.

Encryption and secret management

Data is protected in transit with TLS and at rest using managed cloud encryption. New integration credentials are written to KMS-encrypted columns or managed secret stores.

Identity and access

Signed, expiring sessions, role-aware authorization, credential revocation, and service identities limit access to protected resources.

Application security

Controls include CSP, frame protection, output sanitization, SSRF defenses, request validation, and rate limiting.

File and content safety

Supported upload and import flows apply file-type, size, path, and content checks, including malware screening where configured.

Monitoring and response

Security-relevant events, authorization failures, service errors, and abuse signals support investigation and incident response.

Data governance

Clear boundaries for customer data

We use customer data to provide and secure the services customers configure. We do not sell customer data, and we document the providers and controls involved in processing it.

Inference is not training

Expertise does not operate a customer-content training pipeline. Configured AI providers may process content for inference to deliver the requested feature under applicable data terms.

Subprocessor transparency

Core infrastructure and feature-dependent providers are documented so customers can understand where processing occurs.

Retention and deletion

Retention follows the product and your agreement, and deletion and data-erasure controls are documented in our Trust Center and DPA.

Optional features, your choice

Some capabilities involve additional providers. Data goes only where the features you enable require it.

FAQ

Frequently asked questions

Short answers to what security teams ask us most. Reports, policies, and full documentation live in our Trust Center.

Visitor input, retrieved content, and integration data are always treated as untrusted. The Expertise assistant goes further: skills are screened before they run, execution is sandboxed, credentials stay in the backend, and consequential actions pass through server-side policy and human approval. Because those boundaries live outside the model, a prompt cannot talk its way into new systems or credentials.

The OAuth scopes you grant set the ceiling, and actual access is narrower still — limited by the connected CRM user's own permissions, your configuration, and the workflows you enable. Many customers connect a dedicated integration user with restricted object and field access, and you can revoke the connection at any time.

Expertise has no pipeline that trains models on customer content. Your data is sent to the AI providers you configure only to generate responses, governed by the applicable provider terms and your agreement with us.

Only the providers needed to run the service — infrastructure, model inference, security, support, and any optional features you turn on. We do not sell customer data. The current subprocessor list lives in our Trust Center.

Only what your enabled workflows need, and integration credentials are always stored separately from business data. Storage and retention for your specific configuration are documented in our Trust Center and your agreement.

Bring evidence to your security review

Access our reports, policies, subprocessors, and data-protection documentation—or contact us for deployment-specific answers.