Trust and safeguards
Security
How Engage AI protects accounts, customer information and business operations while keeping people in control.
- Version
- security-2026-08-03
- Effective date
- 3 August 2026
Read this document together with the related policies and any approved customer order form.
Security model and shared responsibility
Engage AI uses layered application, identity and operational safeguards. We protect the platform and its managed infrastructure; customers remain responsible for their users, connected channel accounts, approved business content, endpoint security and lawful communications.
Security-sensitive business changes are executed by deterministic services rather than by an AI model alone. Customers should configure the minimum capabilities and permissions needed for their teams.
Identity and access management
Users authenticate before entering an operational workspace. Role and permission checks protect administrative, billing, content, reporting and conversation actions. Tenant context is validated on protected requests and customer-owned data is queried within that tenant boundary.
Public signup uses short-lived verification and resume tokens. Pending signup sessions use secure host-only cookies, session rotation and CSRF protection; tokens are not placed in analytics identifiers or public page URLs after use.
- Use unique user accounts and strong passwords; do not share credentials.
- Review role assignments promptly when responsibilities change.
- Secure administrator email accounts and connected provider consoles.
Workspace and tenant separation
Workspace data, settings and operational actions are tenant-scoped by default. Platform-only operations require separate authorization, and cross-tenant access is denied by service and repository checks.
Audit records support review of important administrative, automation, billing and lifecycle events without intentionally placing passwords, card details or raw provider credentials into public analytics.
Application and browser protection
The public site and authenticated application use restrictive security headers, a nonce-based content security policy and explicit origin allowlists. Personalized signup and billing routes are non-indexable and use no-store caching rules.
Public endpoints apply input validation, generic account-discovery responses and abuse controls. Security cookies use Secure, SameSite and HttpOnly attributes where the browser must not read the credential.
Data, credentials and payment information
Provider credentials, signing secrets and encryption keys remain in protected server-side configuration or secret references. Sensitive values are masked in administrative views and excluded from browser bundles.
Payment card details are collected through provider-hosted components and are not submitted to Engage AI application servers. Provider references used for reconciliation remain server-controlled.
AI safety and human oversight
Engage AI grounds automated answers in approved business information and exposes capability controls to authorized teams. An AI response does not independently authorize billing, account, appointment or other business-critical writes.
Teams can review history, take over conversations and use escalation paths when confidence is low, an intent is unsupported or judgement is required.
Monitoring, incidents and recovery
Operational logs, audit events, scheduler records and provider events support fault and security investigation. Logs are designed to redact secrets and avoid unnecessary customer content.
Security events are assessed, contained, investigated and remediated according to documented operational procedures. Where notification is required, the responsible operator will follow applicable law and contractual obligations.
Backups, migration verification and recovery procedures form part of release readiness. Exact production recovery objectives and incident contacts require operational approval before live enablement.
Service providers and assurance
Engage AI uses provider boundaries for messaging, AI, calendar, email and payment capabilities. Integrations must pass configuration, credential and readiness checks before use, and customers may need separate provider accounts or terms.
We will publish verified subprocessors and material assurance information when approved. We do not display unsupported security badges or certification claims.