Security Policy

Last updated: June 25, 2026

1. Our Security Commitment

CoSupport AI is committed to protecting your data with the highest level of security. We implement enterprise-grade security measures across our entire infrastructure.

2. ISO 27001 Certification

We are compliant with ISO 27001 — the international standard for information security management systems. Our certification demonstrates our dedication to systematic and documented security practices.

  • Annual third-party security audits
  • Documented security policies and procedures
  • Regular risk assessments and management reviews
  • Continuous monitoring and improvement

3. GDPR Compliance

We are fully compliant with the General Data Protection Regulation (GDPR). This means:

  • Lawful, fair, and transparent processing of personal data
  • Data minimization — we only collect what is necessary
  • Your data is used only for the purposes you consented to
  • You can request deletion of your personal data at any time
  • Data portability — we can export your data in a machine-readable format
  • All AI processing of EU citizens' data is performed within GDPR-compliant infrastructure

4. CCPA Compliance

We comply with the California Consumer Privacy Act (CCPA):

  • Right to know what personal data is collected
  • Right to delete personal data
  • Right to opt out of the sale of personal data (we do not sell data)
  • Right to non-discrimination for exercising your CCPA rights

5. Data Encryption

  • Encryption in transit: All data transmitted to and from our services uses TLS 1.3 encryption. This protects your data from interception during transmission.
  • Encryption at rest: All stored data is encrypted using AES-256 encryption to protect against unauthorized access.
  • Database encryption: All customer databases are encrypted at the storage level.
  • Backup encryption: All backups are encrypted with separate encryption keys.

6. Infrastructure Security

  • Cloud infrastructure: Hosted on secure, globally distributed cloud infrastructure with physical security controls.
  • Network segmentation: Production systems are isolated from other environments.
  • Firewall protection: Enterprise-grade firewalls and DDoS protection.
  • Intrusion detection: Continuous monitoring for suspicious activity.
  • Vulnerability scanning: Regular automated and manual security testing.

7. Access Controls

  • Principle of least privilege: Employees only have access to the systems they need for their roles.
  • Multi-factor authentication (MFA): Required for all internal systems and admin access.
  • Role-based access control (RBAC): Granular permissions management for all systems.
  • Access logging: All access to production systems is logged and audited regularly.
  • Access reviews: Quarterly reviews of employee access rights.

8. AI & Data Privacy

Your ticket data is used solely to provide AI-powered customer support automation. We implement strict controls:

  • No data sharing with third parties: Your data is never sold or shared with advertisers.
  • AI model training isolation: Each customer's data is used only to train their own AI model.
  • Anti-hallucination architecture: Our proprietary AI system includes validation layers to ensure responses are accurate and grounded in your knowledge base.
  • Human-in-the-loop: AI responses can be reviewed and approved by human agents before being sent to customers.

9. Incident Response

In the event of a security incident:

  • Our security team is notified within 15 minutes of detection
  • Incident assessment and containment within 1 hour
  • Affected customers are notified within 72 hours per GDPR requirements
  • Post-incident review and remediation within 14 days
  • Full incident documentation and lessons learned

10. Security Best Practices for Users

  • Use a strong, unique password for your CoSupport AI account
  • Enable multi-factor authentication in your account settings
  • Regularly review connected helpdesk integrations
  • Rotate API keys periodically
  • Report any suspicious activity to support@cosupport.ai

11. Compliance Certifications

ISO 27001

Information Security

GDPR

EU Data Protection

CCPA

California Privacy

12. Contact Security Team

For security-related inquiries, vulnerability reports, or compliance questions:

Email: support@cosupport.ai
Response time: Within 24 hours
Emergency: For critical security issues, please email with subject "SECURITY INCIDENT"