What your security team will ask about.
This product holds your customer conversations, your support history and your revenue numbers. Below is what we enforce and where the enforcement actually happens. Where we fall short of what an enterprise expects, that is on the page too.
Isolated at the database level.
One workspace's records cannot be read from another workspace's session. The rule lives in the database, so a mistake in application code does not open a path around it.
PostgreSQL row-level security is enabled and forced on 321 tables. Each carries an isolation policy tied to the workspace on the session, and no role can be granted an exception.
Within a workspace, records are filtered by ownership and role: a CSM sees their own accounts and meetings. The database roles that can bypass those policies are reserved for sign-in and run on a separate connection pool.
Encrypted in transit. Stored credentials (integration keys, OAuth tokens, model API keys) are encrypted with AES-256-GCM before they reach the database, and the API returns only a last-four hint, never the value.
Retention is set per data category. Outlook email can be summarised and the content deleted immediately afterwards. You configure how long recordings live.
Recording requires attested consent, follows a workspace privacy policy, and writes to an audit table. Our own recorder is the only source. The Teams and Zoom connectors contribute metadata and transcripts but cannot pull provider recording media. For surveys, the privacy mode set at build time decides whether a respondent can be named.
Configuration exports as portable packages, translations as CSV. A vendor in this category recently shut down with twenty-six days' notice and no migration path.
Checked on the server for every request.
A hidden button is not access control. When a request arrives that the user is not entitled to make, the server rejects it, including requests that never came through our interface.
We do not train on your data. No hedge.
Not to improve our models, not for benchmarking, not in aggregate, not anonymised, and not “to inform how the assistant responds later”. Your customer conversations are yours. It is written into the contract, so we cannot quietly change our minds. Aggregated usage and performance data (which features get used, error rates, how long a page takes to load) is a separate thing: it describes our software, not your customers, and never contains customer content.
We use providers under zero-retention terms, so prompts are not stored on their side either. Which provider, and whether one is involved at all, is set below.
Every model call writes an audit row: workspace, user, feature, provider, model, token counts, latency, whether a fallback was used, and which data categories were involved.
For each data category (accounts, contacts, meeting transcripts, email, documents) you decide whether AI may process it, whether an external provider may see it, whether it may be retained, and whether sensitive values are masked first.
A follow-up email is drafted, then stops in front of a person. Nothing reaches your customer from the draft itself. Delivery is a separate step, separately configured, that someone triggers. Field changes heading back to your CRM queue the same way.
The assistant reads through the same role and field-level access as the person asking. Fields hidden from that role never reach the prompt.
Scores show their components and predictions name their model and confidence.
Where it runs, and who else touches it.
The platform runs on AWS in US East. The AI layer is not tied to one vendor: you can use the models we manage, bring your own keys, or point it at a model inside your own network. Everyone who touches your data is named below.
Two operating modes. Use the models we manage, or bring your own account and keys: your provider, your contract, your rate limits.
Point the platform at a model running inside your estate. The endpoint has to be on an allow-list an administrator maintains, so nobody can quietly redirect it somewhere else.
Summarising, reasoning, embedding and transcription are configured separately, each with its own token ceiling, daily cap and fallback rule.
Anything marked tenant-selected is off until an administrator in your workspace turns it on and supplies the credentials. Nothing in this table receives your data by default.
We are not certified yet.
ferent.ai is a new company and we do not hold SOC 2 or ISO 27001. Implying otherwise with careful wording would only delay the moment you find out.
An audit report is a third party confirming our controls exist. Until we have one, we will show you the controls themselves, in a live session, with your security team asking the questions.
Row-level isolation, permission enforcement, the AI audit trail and the approval boundary can all be shown running against a live workspace.
Send the questionnaire you use. We answer every question in writing, including the ones where the answer is no.
We will take your security team through the data model, the isolation boundary and the AI request path, and answer your engineers directly.
Run an approved model inside your own environment, set retention per data category, and mask sensitive values before processing. Each one reduces what you have to trust us with.
The commitments on this page go into the agreement: no training on your data, and human approval before anything reaches your customer.
Ask where certification sits in our plans and you get a date, or an honest "not scheduled yet".
If certification is a hard gate for you today, tell us early and we will say so
What we do with data, said in the order you’d ask.
Everything above is how the product is built. What follows is the policy itself. Where the honest answer is “it depends how your administrator configured it”, it says that instead of implying a guarantee.
Four different relationships, four different answers.
A visitor to this site, someone whose employer bought the platform, the administrator who configured it, and a person who never chose us but appears in a customer's records. That fourth group has the least say and is usually left out of pages like this one.
Contact details you send us, and ordinary analytics about pages and referrers. No profiling, no advertising pixels that follow you off the site.
Your account, your activity in the product, and whatever your organisation put in it. Your employer decides what is collected and how long it stays.
The same as any user, plus a record of configuration changes (roles, scoring, integrations, AI policy) attributed to the person who made them.
A contact at one of our customers’ customers, a meeting participant, a survey respondent. You did not agree to anything with us. Your rights sit with the organisation whose workspace holds the record, and the section below says how to reach them.
Most of it is your customers' data, not yours.
The platform holds what a customer success team needs to do its job: accounts, contacts, conversations, support history, survey responses and revenue. You decide what goes in. We hold it on your behalf.
We do not buy personal data, we do not sell it, and we do not enrich your records from data brokers. What you see in the platform is what you or your connected systems put there.
If you are in the room, this section is about you.
Recording is the most sensitive thing the platform does, and the person most affected often did not buy it. So the controls sit on the recording itself.
A recording cannot start without consent being recorded, under a policy your workspace sets. Every recording writes an audit entry.
Retention is configured per data category. Email can be summarised and the content deleted immediately afterwards.
Identified, confidential or anonymous is chosen when the survey is built. An anonymous response cannot be attributed later, including by us.
Some jurisdictions require every participant to consent. The platform gives you the controls; whether you have the permissions is a decision only you can make.
Who to ask depends on whose record you are in.
If you appear in a customer's workspace, that customer controls the record and we act on their instruction. Asking us directly will not be faster, but we will tell you who to ask and pass the request on the same day.
The rest of it
On AWS in US East. Meeting capture can be processed in US East, US West, EU Central or AP Northeast, chosen by your administrator.
Processing happens where the platform is hosted, which is AWS in the United States. So if your organisation is outside the US, using the platform means a transfer to the US, and standard contractual clauses cover it where required. Two things can sit elsewhere: the recording region above, and the AI provider or endpoint your administrator selected. The security page names the current regions.
Held while your agreement is live and for the period it specifies afterwards. Individual categories can be set shorter by your administrator.
What we need to keep you signed in, and analytics on the marketing site. No advertising networks, no cross-site tracking.
Named individually above, not described as a category. If the list changes, customers are notified.
We disclose data when the law compels it. Where we are permitted to tell the affected customer first, we will.
This is software sold to businesses. It is not for anyone under 16 and we do not knowingly collect their data.
The date at the top changes when the text does, and we notify customers of material changes.
Ask us something specific.
Privacy questions go to a person. If yours is really a security question, the sections above have the controls and the subprocessor list.
Send us your questionnaire.
Better to run your security review in week one than discover it in week six. Both routes below open our contact form. Choose "a security review or documentation pack" and it reaches the right people.