Trust center

Security at ForceTeam.AI

How we protect your transcripts, Salesforce metadata, and deployments.

Security at a glance

Key controls for security and compliance reviews.

Encryption

TLS 1.2+ in transit · AES-256 at rest for sensitive data

Access control

Role-based permissions · least-privilege defaults

24/7 monitoring

Centralized logging · anomaly detection · alerting

Backups & recovery

Automated backups · tested restore procedures

Vulnerability management

Dependency scanning · patch cadence · pen testing

Compliance readiness

GDPR-aligned practices · SOC 2 roadmap

How we protect your data

Layered controls across infrastructure, application, and team.

Data protection

We treat customer data as a core asset and apply defense-in-depth controls across the stack.

  • Customer data is logically segregated by workspace and tenant
  • Sensitive credentials and tokens are encrypted and access-controlled
  • Data minimization principles guide what we collect and retain
  • Subprocessors are vetted under written data protection terms

Infrastructure security

Production workloads run on hardened cloud infrastructure with network segmentation and continuous monitoring.

  • Private networking and firewall policies for production services
  • Infrastructure-as-code with peer review and change management
  • Automated patching for OS and container base images
  • DDoS mitigation and WAF protections at the edge

Authentication & identity

Secure sign-in flows and session management protect account access.

  • Salesforce OAuth for org connections, with no Salesforce password storage
  • Session expiration, secure cookies, and CSRF protections
  • Support for enterprise SSO on eligible plans (roadmap)
  • Administrative role separation within workspaces

Incident response

Documented procedures help us detect, contain, and communicate about security events.

  • Defined severity levels and on-call escalation paths
  • Forensic logging retention for investigation
  • Customer notification for confirmed incidents affecting their data
  • Post-incident reviews and corrective action tracking

Disaster recovery

Resilience planning reduces downtime and data loss risk.

  • Regular backup schedules with encrypted storage
  • Recovery time and recovery point objectives defined internally
  • Periodic restore drills for critical systems
  • Multi-region redundancy for core services (where applicable)

Privacy commitment

Security and privacy are jointly owned. See our Privacy Policy for data handling details.

  • No sale of personal data
  • Contractual restrictions on AI provider use of customer content
  • Data subject request processes for GDPR and similar laws
  • Security inquiries: [email protected]

Security FAQ

Common questions from security reviews.

Need a security review?

We provide questionnaires, architecture overviews, and DPAs on request.