Third Party Index

Snapshot 48246

Document
Security page
URL
https://aijency.ai/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
83258 bytes
SHA-256 (raw)
739fd56584052da3d1b5adfeb4d05093d0e5eb2d5dc6cdf968a74378ef539afe
SHA-256 (normalized text)
80b20ac817be17171288cc90a4f26c8c4cf7e35cbf8ee750f76713ac0268f752

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security and Trust
You are handing us
your pipeline.
We built for that.
Aijent talks to your customers and holds their details. That only works if the security underneath it is genuinely enterprise grade, so we built it that way from the first line of code, not after the first customer asked.
Audit completed
We have completed a SOC 2 Type I audit
Ken & Co issued our SOC 2 Type I report on 1 October 2026. Our Type II audit comes next. The report is available to customers and prospects on request, under a non-disclosure agreement.
If you need the report or our control documentation for a security review, email [email protected] and we will send it.
Reviewed by the platforms you already trust
Before we could connect to these platforms, each one put us through its own review or verification. Where there is a public listing, you can check it yourself.
Approved
HubSpot App Marketplace
Listed after HubSpot's app review, which covers scopes, data handling and security practice.
Approved
Google OAuth verification
Verified by Google for calendar access and Meet, including their review of how we request and use each scope.
Approved
Microsoft OAuth verification
Verified by Microsoft for calendar access and Teams.
Approved
Zoom App Marketplace
Published after Zoom's review, which required us to drop a sensitive scope we did not strictly need.
stripe
Payments run entirely on Stripe
Card details are entered on Stripe's own pages and never reach our systems. There is no card field anywhere in our software, so a breach of Aijency could not expose a card number. Stripe is certified to the highest PCI DSS service provider level.
ANTHROPIC
The agent runs on Anthropic's Claude
Anthropic is contractually barred from training on your conversations. They independently hold SOC 2 Type II, ISO/IEC 27001 and ISO/IEC 42001, verifiable on their own trust centre. Those are their certifications, not ours.
The four things that actually matter
In plain English, with no asterisks.
Your data is stored in Australia
Every lead, conversation and transcript is stored in Sydney, on managed PostgreSQL in the ap-southeast-2 region. Data residency you can point to on a questionnaire, not a promise to look into it.
Your conversations never train an AI model
Anthropic, who power the agent, are contractually barred from training on anything your visitors say. That is a binding agreement with us, not a setting we ticked or a policy that can quietly change.
Encrypted the whole way
Everything in transit is protected by TLS, the same encryption your bank uses. Everything sensitive at rest is encrypted with AES-256, and the keys to your CRM connection are encrypted separately again.
Walled off from every other customer
Isolation is enforced by the database itself, on every single query, not by application code remembering to ask. One customer cannot reach another customer's data even if something above it goes wrong.
What we never do
The commitments that are easiest to check and hardest to walk back.
We do not sell your data. Not to anyone, at any price.
We do not use your data for advertising.
We do not track visitors across other websites.
We do not collect browsing history or fingerprint devices.
We do not store IP addresses, user agents or referrers.
How we keep it that way
Security is a habit, not a launch announcement.
Customer data protection
Tenant isolation enforced by the database itself
Encryption in transit (TLS)
Encryption at rest (AES-256)
CRM tokens encrypted separately (AES-256-GCM)
Stored in Australia, ap-southeast-2 (Sydney)
Payments
Card details entered on Stripe, never on our site
Stripe-hosted checkout and billing portal
No card number ever stored, sent or logged by us
Stripe is a PCI DSS Level 1 service provider
Application protection
Static code analysis on merges to main, plus weekly
Secret scanning on merges to main, plus weekly
OAuth 2.0 with PKCE wherever supported
We never hold your CRM password
Infrastructure
Managed PostgreSQL with encryption at rest
Application compute pinned to the Sydney region
Secrets in a dedicated, access-controlled manager
Documented key-management policy
Monitoring and response
Append-only audit log, not editable in the app
Continuous error monitoring, every environment
Uptime monitoring with alerting
Public status page
Privacy and compliance
Australian Privacy Act 1988
GDPR with Standard Contractual Clauses
PDPA (Singapore)
No AI model training on your conversations
Published sub-processor list
Doing a security review?
This page is the plain English version. The full technical detail, written for procurement teams and security reviewers, covers exactly what we collect, how it flows, every control we run and every company that touches your data.
Download the security white paper
PDF, 6 pages. No form to fill in.
Read the full security detailSee every sub-processor
Questionnaires and DPAs: [email protected]
Found a vulnerability?
Report it to [email protected]. We acknowledge every report, we will keep you updated while we fix it, and we will never take action against anyone who reports a genuine issue in good faith.
Live system status
Uptime and incidents are published continuously, not summarised after the fact. If we are having a bad day you will see it here before you have to ask.
View the status page
Ready to turn your website into a 24/7 sales machine?
Start Free Trial