Your customers' data, handled with the same care as your policies.
An agent that can act on accounts, orders and bookings has to be bounded tightly. Here is what we store, how it is protected, who can see it, and what each agent is and isn't allowed to do.
Data handling
What's stored, and for how long.
We store only what the agent needs to answer and what you need to review its work. Records such as orders and bookings are read live through the access you grant, not copied in bulk.
Conversations
Messages between your customers and the agent, and any handoff notes.
Kept for your workspace retention period, then deleted.
Detected context
The intent and the record values the agent looked up to answer, such as an order status or booking time.
Stored with the conversation it belongs to.
Grounding sources
The policies, articles and rules you connect, with version history.
Kept while connected. Removed when you disconnect a source.
Action log
Every action the agent took or prepared, with the limit and policy involved.
Kept for your workspace retention period.
Retention you set
Choose the retention period for conversations per workspace. Deleted data is removed from active systems and then from backups on their normal cycle.
Access scope
Roles control who in your team can view conversations, change policies, edit limits or export data. Access is logged.
Data requests
Export or delete a specific customer's conversations on request, so you can respond to your own customers' privacy requests.
Protection
Encrypted in transit and at rest.
Standard protections, applied everywhere, with nothing left as an opt-in.
In transit
All traffic between customers, your systems and the service is encrypted with TLS.
At rest
Stored conversations, sources and logs are encrypted at rest.
Credentials
Keys and tokens you provide for record access are stored encrypted and never shown in full after entry.
Least privilege
Ask for read access first. Write access is only needed for the actions you choose to automate.
Action boundaries
Every action is configured and capped by you.
An agent can only take the actions you switch on, up to the limits you set. Anything beyond a limit is prepared and routed to a person for approval.
Returns & Orders
- Refund without approval
- Up to your limit
- Exchanges
- Inside your window
- Order edits
- Before dispatch only
Billing & Accounts
- Account credit
- Up to your limit
- Plan changes
- On or off
- Card refunds
- Always a person
Scheduling
- Reschedules
- Up to your count
- Bookings
- Within clinician rules
- Clinical questions
- Always staff
Healthcare deployments
The Scheduling agent works with scheduling and administrative data only: names, contact details, appointment times, clinicians and locations. It does not need, and should not be given, access to clinical records.
Health-data handling and any regulatory requirements that apply to your clinic or region are reviewed and confirmed with you before launch. Clinical questions are never answered by the agent and are passed straight to your staff.
Compliance posture
Current status only. No borrowed badges.
We describe the controls we have in place today, and we don't display certification logos for audits that haven't been completed. If your procurement process needs a security questionnaire, a data processing agreement or details of our sub-processors, ask us and we'll share what applies to your deployment.
If you believe you've found a security issue, please report it through the contact form with the subject “Security”. We review every report and will respond to let you know what happens next.
Which question fills your inbox?
Pick the one that sounds most like your customers. We'll set you up with that agent first.