Security, in plain language
Everything a security review usually asks for, on one page: where your data is hosted, how it is protected, what the AI is allowed to do with it — and the published documents that make those commitments binding.
01Where your data lives
CustomerEagle's primary hosting is in the EU. Where a sub-processor necessarily processes data outside the European Economic Area, that transfer runs on an appropriate mechanism — primarily the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where it applies.
- Primary hosting in the EU.
- AI sub-processors are covered by EU Standard Contractual Clauses.
- Every sub-processor is named in the DPA with its purpose and its processing location — including the ones outside the EU.
02Encryption in transit and at rest
Data moving between the widget, your dashboard, our service and any connected integration travels over TLS. Stored credentials and sensitive personal data are encrypted at rest with AES-256-GCM, and backups are encrypted too.
- TLS for data transmitted between clients, the service and integrations.
- AES-256-GCM encryption for stored credentials and sensitive personal data.
- Encrypted backups, with measures to restore availability and access to personal data after an incident.
03How one workspace stays separate from another
CustomerEagle is multi-tenant, and the separation is enforced in the application: every query that touches customer data is explicitly scoped to a single workspace. PostgreSQL row-level security is configured behind that as a defence-in-depth layer — a second net, not the thing we lean on.
- Per-workspace scoping on every query is the control we rely on.
- Database row-level security sits behind it as defence in depth.
- Staff access is role-based, and platform staff accounts require multi-factor authentication.
- Security-relevant and administrative events are logged to support monitoring and investigation.
04GDPR: the documents, not a summary
You can read what you are agreeing to before you agree to it. The Data Processing Agreement carries the Article 28 terms, the sub-processor list and the transfer clauses; the privacy policy sets out what we process and why; deletion is self-service and documented.
- Self-service export and deletion tools, plus assistance with data-subject requests under Articles 12–23 GDPR.
- We notify you without undue delay after becoming aware of a personal data breach affecting your personal data — an initial notification, where practicable, within 24 hours.
- Sub-processor additions or replacements are announced at least 30 days in advance, with a right to object on reasonable data-protection grounds.
05What the AI is allowed to do with your data
The assistant answers from sources you approved and cites them; when it is not confident, it hands the conversation to your team instead of guessing. Your support data is never used to train general models.
- Answers come only from content you approved, each one cited to its source.
- Order details are shown only to the customer whose e-mail matches the order by default — a wrong e-mail and a missing order return the identical response.
- The AI never issues a refund or edits an order on its own: write actions are prepared and queued for a human to approve.
- Your support data is never used to train general models.
06What we commit to in writing
Our technical and organisational security measures are contractually committed in a public Data Processing Agreement — published for review before you sign, not available on request. The DPA names every sub-processor with its purpose and processing location, and it may only be updated if the level of protection is not materially reduced. If your procurement runs on a security questionnaire, the published documents answer most of it — and we answer the rest directly.
- Security measures contractually committed in the public DPA.
- Updates to the DPA may not materially reduce the level of protection.
- Security questionnaires welcome — most answers are already in the published documents.
07Reporting a vulnerability
If you think you have found a security issue, tell us before you tell anyone else. Use the contact form and say in the first line that it is a security report — our team replies within one business day. Our terms ask for the same courtesy in writing: a reasonable opportunity to investigate and remediate before anything is disclosed publicly.
- Send it through the contact form, marked as a security report.
- Please do not test against real customer data, and no scanning or intrusion testing against production without written permission.
- No service can be guaranteed completely secure — we would rather hear about it early.
Read the documents
We publish the legal texts rather than summarising them. The DPA carries the Article 28 terms, the full sub-processor table with processing locations, and the international-transfer clauses.
Filling in a security questionnaire about us? The DPA and the privacy policy answer most of it — anything they don't, ask. Contact the team