Security Policy
Last updated: June 25, 2026
1. Our Security Commitment
CoSupport AI is committed to protecting your data with the highest level of security. We implement enterprise-grade security measures across our entire infrastructure.
2. ISO 27001 Certification
We are compliant with ISO 27001 — the international standard for information security management systems. Our certification demonstrates our dedication to systematic and documented security practices.
- Annual third-party security audits
- Documented security policies and procedures
- Regular risk assessments and management reviews
- Continuous monitoring and improvement
3. GDPR Compliance
We are fully compliant with the General Data Protection Regulation (GDPR). This means:
- Lawful, fair, and transparent processing of personal data
- Data minimization — we only collect what is necessary
- Your data is used only for the purposes you consented to
- You can request deletion of your personal data at any time
- Data portability — we can export your data in a machine-readable format
- All AI processing of EU citizens' data is performed within GDPR-compliant infrastructure
4. CCPA Compliance
We comply with the California Consumer Privacy Act (CCPA):
- Right to know what personal data is collected
- Right to delete personal data
- Right to opt out of the sale of personal data (we do not sell data)
- Right to non-discrimination for exercising your CCPA rights
5. Data Encryption
- Encryption in transit: All data transmitted to and from our services uses TLS 1.3 encryption. This protects your data from interception during transmission.
- Encryption at rest: All stored data is encrypted using AES-256 encryption to protect against unauthorized access.
- Database encryption: All customer databases are encrypted at the storage level.
- Backup encryption: All backups are encrypted with separate encryption keys.
6. Infrastructure Security
- Cloud infrastructure: Hosted on secure, globally distributed cloud infrastructure with physical security controls.
- Network segmentation: Production systems are isolated from other environments.
- Firewall protection: Enterprise-grade firewalls and DDoS protection.
- Intrusion detection: Continuous monitoring for suspicious activity.
- Vulnerability scanning: Regular automated and manual security testing.
7. Access Controls
- Principle of least privilege: Employees only have access to the systems they need for their roles.
- Multi-factor authentication (MFA): Required for all internal systems and admin access.
- Role-based access control (RBAC): Granular permissions management for all systems.
- Access logging: All access to production systems is logged and audited regularly.
- Access reviews: Quarterly reviews of employee access rights.
8. AI & Data Privacy
Your ticket data is used solely to provide AI-powered customer support automation. We implement strict controls:
- No data sharing with third parties: Your data is never sold or shared with advertisers.
- AI model training isolation: Each customer's data is used only to train their own AI model.
- Anti-hallucination architecture: Our proprietary AI system includes validation layers to ensure responses are accurate and grounded in your knowledge base.
- Human-in-the-loop: AI responses can be reviewed and approved by human agents before being sent to customers.
9. Incident Response
In the event of a security incident:
- Our security team is notified within 15 minutes of detection
- Incident assessment and containment within 1 hour
- Affected customers are notified within 72 hours per GDPR requirements
- Post-incident review and remediation within 14 days
- Full incident documentation and lessons learned
10. Security Best Practices for Users
- Use a strong, unique password for your CoSupport AI account
- Enable multi-factor authentication in your account settings
- Regularly review connected helpdesk integrations
- Rotate API keys periodically
- Report any suspicious activity to support@cosupport.ai
11. Compliance Certifications
ISO 27001
Information Security
GDPR
EU Data Protection
CCPA
California Privacy
12. Contact Security Team
For security-related inquiries, vulnerability reports, or compliance questions:
Email: support@cosupport.ai
Response time: Within 24 hours
Emergency: For critical security issues, please email with subject "SECURITY INCIDENT"