What we are certified against, the controls we run, and everything your security team can ask us for.
Our agents read and write the systems that run your business, so how we handle your data is not a footnote. This page sets out what we are certified against, the controls we operate, who else may touch your data, and what you can ask us for.
If your security or procurement team needs something that is not here, contact us and we will answer directly rather than send you to a portal.
The 33 controls below sit inside our ISO/IEC 27001 information security management system, grouped by the themes the standard uses.
Each is bound by contractual data protection terms and receives only the data required for its function. Material changes are published under Updates.
| Subprocessor | Purpose |
|---|---|
| Cloud infrastructure and hosting | |
| Language model processing | |
| Language model processing | |
| Language model processing | |
| Network delivery and protection | |
| Messaging delivery | |
| Messaging delivery | |
| WhatsApp Business messaging | |
| Database hosting |
Any third party that stores, transmits or processes customer data as part of delivering our service, including infrastructure providers and the model providers behind our agents. It does not include systems you already run and we simply integrate with, such as your own ERP or CRM, since that data never leaves your control.
Before a subprocessor is engaged we assess its security posture, the data it would touch and the region it operates in. Engagement depends on contractual data protection terms that hold it to standards no weaker than our own.
We engage as few subprocessors as the service allows, and each receives only the data it needs to do its job. The model providers behind our agents operate under zero data retention, so customer content is not held by them after processing.
The current list is provided to customers and to prospective customers going through a security review. Material changes are published under Updates and notified to customers under contract.
Our current certificate is available on request, together with the scope statement describing exactly what the certification covers.
Send us the questionnaire your organisation uses and we will complete it. If your team would rather speak to the people who built the integration, we will arrange that too.
Provided to customers and to prospective customers under review. How the list is managed is described under Subprocessors.
Our privacy policy and accessibility statement are published on this site and need no request. Links are in the footer of every page.
We are pleased to announce that Automatiq.ai has officially achieved ISO/IEC 27001 certification, the international standard for information security management. The certification covers how we manage information security across our systems, our people and our suppliers, and it is maintained through regular audit. The certificate and its scope statement are available on request under Resources.
Changes to our certifications, additions or removals from the subprocessor list, changes to where data is processed, and any security incident affecting customer data.
Customers under contract are notified directly through their named contact, in line with the notice periods in their data processing terms. Anyone evaluating us can ask to be added to the same notifications.
Our incident response process covers detection, containment, customer notification and a review afterwards. Where an incident affects customer data, affected customers are contacted directly rather than left to find a notice on a page.
Send us your questionnaire and we will answer it directly, and share our current documentation.
Contact Our Team