What we do to protect your customers' data, stated plainly. If a control is not in place yet, this page says so.
SOC 2 readiness in progress (not certified)
TLS 1.2 or higher on every connection, with HSTS.
AES-256 encryption at rest for the database and file storage (Supabase on AWS), plus AES-256-GCM application-layer encryption for integration tokens and credentials.
Two-factor authentication (authenticator app) is available to every user in Settings, Security. Requiring it for a whole team is not available yet.
Single sign-on (SAML or OIDC) is not available yet.
Sign-in and sign-out events are not recorded in this log yet.
Conversations, transcripts and attachments are kept until you delete them, unless you set a retention window per company (30 days to 2 years) in the agency console. Until deletion is switched on, a window is a preview and nothing is deleted.
After an account ends, we delete its data on written request within 30 days, and confirm in writing.
Session replay runs on our website, and inside the product with the visible text and form fields masked (images are not masked); it never runs in the agency console or on your customers' chat pages.
SOC 2 readiness work is underway; Corebee is not SOC 2 certified and has no SOC 2 report yet.
The full agreement with a plain-English summary.
Template for signature. Have your counsel review it.
22 vendors, what each one processes and where. Last changed 2026-09-26.
Encryption, access control, AI guardrails and data handling in detail.
What Corebee collects about its own users and visitors.
Report a vulnerability or ask a security question: jonathan@corebee.ai.