Approved sources
Choose the pages, documents, policies, and product information the assistant can use.
Protect the business information, website conversations, and phone calls used by your AI assistant or AI receptionist with controls your team can verify.
7-day free trial
InsertChat keeps answers tied to approved sources, on brand, and under your control before launch.
Choose the pages, documents, policies, and product information the assistant can use.
Show citations and links so visitors can trust the response.
Shape tone, wording, welcome messages, suggested prompts, and assistant behavior.
Control who can manage sources, review conversations, update settings, and publish changes.
Protect visitor and workspace data with secure controls.
Current control scope, data flow, subprocessor roles, review dates, and a direct evidence-request path for legal, security, and procurement teams.
SOC 2 Type II examined. GDPR and CCPA aligned. HIPAA eligibility is limited to approved Enterprise deployments with an executed BAA. Evidence covers the InsertChat production service and documented supporting controls.
TLS protects data in transit; AES-256 protects stored customer data. Least-privilege access, secure authentication, audit logs, and documented personnel controls apply to production access.
Documented monitoring, vulnerability management, escalation, containment, recovery, and customer-notification paths support the production service. Security concerns can be routed directly for review.
The current provider-level schedule, processing location, transfer mechanism, and change-notice terms are included in the DPA and evidence packet.
Trust materials last reviewed August 19, 2026
Request the current report, DPA/SCC package, provider-level subprocessor schedule, security questionnaire, or a scoped consultation. Do not include credentials, PHI, or customer data in the request.
From approved sources and visitor conversations to retention, deletion, and privacy requests.
We collect only needed data, limit access, and delete it when no longer required.
Each deployment can define what source content, visitor information, and connected systems belong in scope.
Security review can cover source scoping, access, encryption, retention, subprocessors, and rollout controls before launch.
Customer prompts, files, conversations, and visitor data are not used to train AI models.
We retain customer data only as long as required to provide services or satisfy legal obligations, then securely delete it.
We support access, rectification, erasure, portability, and restriction requests with systems designed for fast response.
Protection across hosting, application access, monitoring, and response.
The day-to-day practices that support the security setup.
Team members complete background checks before accessing sensitive systems.
Regular security awareness training keeps every employee aligned with current best practices.
Security issues are handled through documented response, escalation, and customer communication paths.
SOC 2 Type II examined. GDPR and CCPA aligned. HIPAA-ready. We never train AI on your data — and we never share it.
Tap any question about the product, pricing, security, or setup to see a straight answer.
InsertChat
Answers about InsertChat
Hi! Tap any question below and I'll answer it for you.
European servers. GDPR-ready, never used for training, and deletable at any time.
InsertChat connects approved sources to AI models. Privacy depends on sources, enabled tools, and who can access the assistant.
Your prompt and relevant context excerpts from connected sources are sent to the selected model provider to generate an answer.
No. InsertChat never uses your data to train models.
Yes. Data is scoped to your account and agents. Sources and conversations remain isolated.
Yes. Delete sources, conversation history, leads, and feedback at any time.
Agent configuration, connected knowledge sources, and conversation data needed for the experience and analytics.
Yes. Choose public or private agents depending on whether anyone or only authenticated users can access the embed.
Yes. Control who can manage agents and data with role-based access.
You provide the model API key. Prompts and context still go to that provider, so review its policies.
Yes. Control tool enablement per assistant to limit actions to only what is necessary.
Yes. Scope sources to what should be answerable and limit tool enablement to only what is required.
Yes. Analytics show what people ask. Contact us for exports for audits or internal reporting.
Yes. Full GDPR compliance with Data Processing Addendum (DPA) available on request.
Yes. Our DPA covers processing obligations, subprocessors, and deletion/return terms. Contact us to request it.
Yes. Subprocessors are documented in the DPA. Request it or contact us for details.
Contact us and we provide the right documentation for your security review process.
Yes, when configured correctly. Ground answers in approved sources and keep tool access controlled.
Enterprise plans cover custom deployment, advanced controls, and procurement constraints. Contact us to discuss.
Submit privacy requests through the contact page. We route them to the right process.
Submit security inquiries through the contact page.
Not as a standard plan entitlement. Enterprise buyers can review deployment requirements with sales before purchase.
Start with non-sensitive data during the free trial. When ready, request our security questionnaire and DPA.
We can support security questionnaires, privacy review, DPAs, subprocessors, and rollout planning before a branded assistant goes live.
7-day free trial