How we protect your data.
Overview
Security at Acme
Acme Corp operates a SOC 2 Type II certified platform. This page carries our current certifications, policies and subprocessor list so your security review can start without an email thread. Documents marked with a lock require a short access request and an NDA.
SOC 2 Type II
Prescient Assurance
Valid to Sep 2026
ISO 27001:2022
BSI
Valid to Mar 2027
GDPR
CCPA
Documents
Subprocessors
The third parties that process customer data on our behalf. Subscribe below to be notified before we add a new one.
| Subprocessor | Purpose | Data | Region |
|---|---|---|---|
Amazon Web Services DPA | Cloud infrastructure and data storage | Customer content, Account data | United States |
Anthropic AI providerDPA | AI model inference for support drafting and questionnaire answers | Customer content | United States |
OpenAI AI providerDPA | Text embeddings for document retrieval | Customer content | United States |
Stripe DPA | Payment processing | Billing data | United States |
Gong AI providerDPA | Sales call recording and summarisation | PII, Call recordings | United States |
AI
- Do you use AI in the product?
- Yes. 6 AI systems are in production.
- Is customer data used for training?
- Some internal models are trained on aggregated product telemetry. Customer content is never used to train third-party models.
- Which providers process data?
- Anthropic, OpenAI, Gong
- Where is data processed?
- us-east-1
Human oversight
- A person reviews every output before it is used
- No human-facing output
- A person monitors outputs and can intervene
Data categories processed by AI systems
- Customer content
- Product telemetry
- Personal data
Generated from Acme Corp’s AI system inventory on August 6, 2026. This page is derived from the inventory, not written by hand, so it cannot drift.
Contact
Questions this page does not answer? Reach our security team at security@acme.com. We respond within one business day.