Built to pass your security review
AIcelerate handles enterprise revenue pipelines. That means zero model training on your data, jurisdictional compliance, and strict isolation.
Security SLAs
We move at the speed of your procurement team. Send us an NDA and we will unblock your legal and IT review immediately.
Request Security PackageSetting the standard for responsible AI
Your pipeline data stays strictly within your tenant. Here is how we enforce it.
Zero Data Training
Customer data is never used to train models. Yours or anyone else's. Your pipeline data stays strictly within your tenant.
SOC 2 Type II
Independent third-party audit covering security, availability, and confidentiality controls.
GDPR Compliant
Fully compliant data handling. Standard DPAs issued within 48 hours. Custom DPAs negotiated with a 5-business-day SLA.
Full Audit Trail
Every action, every approval, and every system call is logged and retained for the life of the contract. Fully visible to your CRM admins.
End-to-End Encryption
Deployed on GCP infrastructure. Data is encrypted at rest (AES-256) and in transit (TLS 1.3).
Independent Security Scans
Continuous vulnerability scanning and penetration testing conducted via Detectify.
Cyber Insurance
Comprehensive cyber liability and technology errors and omissions insurance backed by Vouch.
Bring-Your-Own-Data (VPC)
AIcelerate runs inside your VPC. Zero data egress. Your customer data never leaves your perimeter.
Salesforce AppExchange
Native in-CRM views, logged activity, and full audit trails visible directly to your Salesforce administrator.
Security commitments
These are the commitments we make to every customer whose revenue data we process, and the ones we hold ourselves to internally. They apply whether you run AIcelerate in our environment or inside your own VPC.
Confidentiality and least privilege
Customer data is treated as confidential. Internal access is granted on a need-to-know basis, tied to a named role, reviewed periodically, and revoked when it is no longer required.
Encryption everywhere
Customer data is encrypted in transit with TLS 1.3 and at rest with AES-256 across our GCP infrastructure. Credentials and integration tokens are held in managed secret storage, never in application code.
No model training on your data
We do not use customer data to train or fine-tune models — yours or anyone else's. Your pipeline data stays within your tenant and is processed only to deliver the service you contracted for.
Traceability and integrity
Every agent action, approval, and system call is logged and retained for the life of the contract, and is visible to your administrators. Nothing the platform does on your behalf is unattributable.
Availability and recoverability
Production systems are monitored continuously, backed up, and restorable. Availability commitments and recovery objectives for your deployment are set out in your agreement.
Secure development and vulnerability management
Changes are peer-reviewed before release. We run continuous dependency and vulnerability scanning, plus independent external scanning and penetration testing via Detectify, and remediate on a severity-based schedule.
Incident response and notification
We maintain a documented incident response process with defined roles and escalation paths. If an incident affects your data, we notify you without undue delay and no later than 72 hours after we become aware of it, and we keep you updated through resolution.
Personnel security
Everyone with access to production is bound by confidentiality obligations and completes security awareness training. Access is provisioned on joining and removed on departure.
Subprocessor due diligence
Subprocessors are reviewed for security and privacy posture before onboarding and are contractually bound to equivalent obligations. The current list is available on request under NDA.
Retention and deletion
You keep control of your data. We retain it only as long as needed to provide the service or as required by law, and we return or delete it on request and on termination.
Independent verification
We operate against GDPR, CCPA, and UAE PDPL requirements, and our SOC 2 Type II audit covering security, availability, and confidentiality is in progress. Reports and questionnaire responses are shared under NDA.
A published way to reach us
Anyone — customer, researcher, or member of the public — can report a suspected vulnerability or security concern to a monitored security inbox and get a human response. Reports made in good faith are welcome.
Report a security concern
Found a vulnerability, or worried about something you have seen? Tell us. This channel is open to everyone — customers, prospects, and independent security researchers alike. You do not need an account, an NDA, or an existing relationship with us to use it.
Security reports
security@aicelerate.aiMonitored by the AIcelerate security team. Acknowledged within 1 business day.
If you cannot reach that inbox, write to a.ignatov@aicelerate.ai and mark the subject line urgent. Please do not report vulnerabilities through public channels such as social media or our contact form.
What to include
- What you observed, and the URL, endpoint, or component involved
- Steps to reproduce, with request/response detail or a short proof of concept
- Your assessment of the impact and who could be affected
- How you would like to be credited, if the report leads to a fix
What happens after you report
You report
Email security@aicelerate.ai with what you found. No account, NDA, or existing relationship required.
We acknowledge
A member of the security team confirms receipt within 1 business day and asks for anything else we need to reproduce the issue.
We triage
Within 3 business days we validate the report, assign a severity and a named owner, and tell you what we found.
We fix and close the loop
Weekly updates until the issue is resolved, then confirmation of the fix. Where a report affects customer data, affected customers are notified directly.
Coordinated disclosure
- Report in good faith and we will not pursue legal action over your research.
- Give us a reasonable window to remediate before publishing — we will agree a timeline with you.
- Work only against your own accounts and data. Do not access, modify, or exfiltrate anyone else's.
- No denial of service, spam, social engineering of our staff or customers, or physical attacks.
Machine-readable contact details are published at /.well-known/security.txt.