The answers procurement teams usually ask for, pre-filled (CAIQ-lite format). Print or save as PDF and attach to your vendor review; for a full CAIQ/SIG spreadsheet, email hello@example.com.
Yes — hello@example.com, 72-hour response commitment for security reports.
Yes — access control, incident response (72-hour breach notification runbook), retention and secure development practices; summarized on the Security page.
Not yet certified. Compensating evidence: this questionnaire, a public sub-processor register, signable DPA, audit logging, and the controls below. Certification is on the roadmap; ask for current status.
Yes — TOTP 2FA for all users; enforceable per account.
Yes — SAML 2.0 SSO and SCIM provisioning on all plans.
Yes — owner/admin/supervisor/agent roles; brand-scoped admin access for agencies; conversation-level ownership guards.
Yes — per-account IP allowlisting (IPv4/IPv6, CIDR).
Yes — TLS 1.2+ for all traffic, including webhooks (HMAC-signed payloads).
Credentials, API keys, TOTP secrets and provider secrets are application-layer encrypted (AES-256 via Laravel Crypt). Disk-level encryption per hosting provider.
Yes — every query is tenant-scoped at the ORM layer with middleware-enforced binding; isolation is covered by automated tests.
Card numbers and CVVs are detected (Luhn + network prefix) and masked before storage on every channel — transcripts, backups and AI calls stay out of PCI scope. Subscription payments go directly to Stripe/Razorpay.
No. AI providers are called with your own API key under your terms; card data is redacted before any AI call.
Yes — self-serve at /dpa, incorporated into the terms, countersigned copies on request. EU SCCs (2021/914 Module 3) for international transfers.
Yes — per-person JSON export and audited erasure (profile, sessions, page views, conversations, leads, tickets) from the console; automated retention purge per account.
The widget ships a strict consent mode (no cookies/tracking until CMP consent or chat start), configurable recording notices with logged consent receipts, and default-on AI disclosure (EU AI Act Art. 50).
Affected customers without undue delay, at most 72 hours after awareness, with scope/impact/mitigation details; we assist onward regulator notifications (GDPR Art. 33, DPDP Board).
Yes — a tenant-visible audit trail covers exports, erasures, settings changes, action runs and license events.
Yes — /status (live) and /sla.
Automated daily database backups with retention, restore-tested; backups inherit the same access controls.
Code review, automated test suite in CI (unit + feature), dependency updates via Composer audit, SSRF guards on all outbound fetches.
Version 1.0 — August 2026. Answers reflect the shipped product; verify current status for certification claims.