Security
Your data security is our priority
We build security into every layer of the PressTwo platform. Here's how we protect your business data and your customers' conversations.
Infrastructure Security
Our platform is hosted on Vercel and Supabase, industry-leading infrastructure providers with SOC 2 Type II compliance.
- All infrastructure runs on isolated, managed environments with automatic security patches
- Network traffic is encrypted in transit using TLS 1.2 or higher
- Database connections are encrypted and access is restricted to authorized services only
- Automatic DDoS protection and rate limiting at the edge
Data Encryption
- In transit: All data transmitted between your browser, our servers, and third-party services is encrypted using TLS 1.2+
- At rest: All stored data, including Knowledge Base Data, conversation logs, and account information, is encrypted using AES-256
- API keys and secrets: Stored using encrypted environment variables, never committed to source code
Data Isolation
- Each customer's data is logically isolated using row-level security policies
- Knowledge Base Data is scoped to individual bots — no cross-contamination between customers
- AI model inference requests are stateless — conversation context is not persisted by the AI provider
- Your data is never used to train AI models or shared with other customers
Authentication and Access Control
- User authentication is handled by Supabase Auth with bcrypt password hashing
- Session tokens are HTTP-only, secure, and scoped
- API endpoints are protected by authenticated middleware — no anonymous access to customer data
- Bot widget endpoints verify bot ownership before serving configurations
AI Model Security
- Language models are served by Anthropic (Claude) and embeddings by Voyage AI, both accessed over authenticated, encrypted API connections
- Your data is never used to train any model. Anthropic does not train its models on data submitted through the API — this is a contractual commitment, not a setting we toggle
- Your Knowledge Base Data is injected as context at inference time and discarded after the response — it is never fine-tuned into a model
- Prompts include guardrails against prompt injection and jailbreaking; retrieved content is treated as data, never as instructions
- Every response is logged with its sources so you can audit what the model saw and why it answered as it did
Regulated Data
Some of our customers operate in regulated industries. We support those deployments with additional controls and contractual terms.
- Healthcare (HIPAA): We sign Business Associate Agreements for HIPAA-eligible deployments. Protected health information is handled under the same encryption, isolation, and access controls described above, with retention configured to your requirements.
- Financial services (GLBA): For lenders, brokers, and financial institutions, nonpublic personal information is treated as regulated data end to end — encrypted in transit and at rest, isolated per customer, never used for training, and retained only as long as your policy requires.
- Data minimization: Our agents are configured to refuse sensitive identifiers they do not need. A deployment that has no reason to collect a Social Security number is configured to decline one if a visitor offers it.
- Human in the loop: For regulated decisions, our tools are built to inform a licensed professional rather than to decide autonomously — with every figure traceable to its source document.
Data Retention and Deletion
- You own your data. Knowledge base content, conversation logs, and captured leads belong to you, not to us
- You can delete a knowledge base document, a conversation, a lead, or an entire agent from your dashboard at any time
- Closing your account removes your data from production systems; backups age out on their normal cycle
- Custom retention windows — including shorter ones for regulated deployments — are available on request
- Export your conversation and lead data at any time; we do not hold it hostage
Payment Security
- All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor
- We never store credit card numbers, CVVs, or full payment details on our servers
- Billing portal and subscription management are handled through Stripe's secure hosted pages
Incident Response
- We maintain an incident response plan for security events
- Affected customers will be notified within 72 hours of a confirmed data breach
- Post-incident reviews are conducted to prevent recurrence
- Application errors and performance are continuously monitored, with a public health endpoint for uptime checks
Subprocessors
We believe you should know exactly who touches your data. These are the vendors that process customer data on our behalf.
| Vendor | Purpose |
|---|---|
| Vercel | Application hosting and edge delivery |
| Supabase | Database, authentication, file storage |
| Anthropic | Language model inference (Claude) |
| Voyage AI | Text embeddings for knowledge retrieval |
| Retell AI | Voice agent telephony and speech |
| Upstash | Rate limiting and abuse protection |
| Stripe | Payment processing and billing |
| Resend | Transactional email (lead alerts, digests) |
| Sentry | Error monitoring and diagnostics |
Voice features are only engaged on plans that include them. Customers on chat-only plans have no data processed by our voice subprocessor.
Compliance Posture
We would rather be precise about this than impressive, because your compliance team will check.
- The infrastructure PressTwo runs on is certified: Vercel and Supabase hold SOC 2 Type II, and Stripe is PCI DSS Level 1. Their certifications cover their platforms.
- PressTwo does not yet hold its own SOC 2 attestation. It is on our roadmap. Any vendor claiming otherwise by pointing at their hosting provider's certificate is telling you something misleading, and we would rather not.
- We complete vendor security questionnaires, sign BAAs where applicable, and will walk your security or compliance team through any control on this page.
- Custom terms — retention limits, deletion SLAs, regional processing — are available for enterprise deployments.
Have security questions?
We're happy to discuss our security practices in detail or complete your vendor security questionnaire.
Contact Our Team