Your Data Stays Yours. Always.

AES-256 encryption at rest and in transit. Zero data training — your content never improves third-party models. European servers, GDPR compliant, enterprise-grade infrastructure. Built so your team can deploy AI agents without compromising on data governance.

Enterprise-Grade AES-256 Encryption Zero Data Training
Start your secure trial

7-day free trial · Cancel anytime · No commitment

Enterprise security
features

Built-in protections for teams handling sensitive data.

Enterprise-Grade Security

Built around five trust principles: security, availability, processing integrity, confidentiality, and privacy — with ongoing monitoring and regular security assessments.

AES-256 Encryption

All data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3 protocols.

Zero Data Training

Your data is never used to train AI models. We maintain strict data isolation and privacy controls.

Bring Your Own Key

Enterprise customers can manage their own encryption keys for ultimate control over data access.

Role-Based Access Control

Granular permissions ensure users only access data and features necessary for their role.

24/7 Monitoring

Continuous security monitoring with real-time threat detection and automated incident response.

Data protection
principles

How we handle your data at every stage.

Data Minimization

We collect only the data necessary to provide our services and delete it when no longer needed. Our systems are designed to minimize data exposure and limit access to what's absolutely required.

Data Residency

Customer data is stored in secure data centers within your chosen region. We offer data localization options to meet specific regulatory requirements and ensure data sovereignty.

Data Retention

We retain customer data only for as long as necessary to provide services or as required by law. Clear retention policies ensure automatic deletion of expired data with secure disposal methods.

Data Subject Rights

We support all data subject rights including access, rectification, erasure, portability, and restriction of processing. Our systems enable quick response to individual rights requests.

Infrastructure
security

Multiple layers of protection across our entire stack.

Cloud Security

  • badge 13European infrastructure with DDoS protection
  • badge 13Multi-region deployment for high availability
  • badge 13Automated security patching and updates
  • badge 13Isolated network environments

Application Security

  • badge 13Secure coding practices and code reviews
  • badge 13Regular penetration testing
  • badge 13Vulnerability scanning and management
  • badge 13Web application firewall (WAF)

Access Controls

  • badge 13Multi-factor authentication (MFA) required
  • badge 13Secure authentication workflows
  • badge 13Principle of least privilege
  • badge 13Complete audit logs

Monitoring & Response

  • badge 1324/7 security monitoring
  • badge 13Real-time threat detection
  • badge 13Automated incident response
  • badge 13Comprehensive logging and alerting

Our security
team

Led by experienced security professionals with backgrounds at top technology companies.

Background Checks

All team members undergo comprehensive background checks to ensure the highest security standards and trustworthiness.

Security Training

Regular security awareness training for all employees to maintain the highest level of security consciousness and best practices.

Incident Response

Dedicated security team with 24/7 incident response capability to quickly address and resolve any security concerns.

Compliance and
certifications

Standards we meet and maintain.

badge 13
Enterprise Security

Certified

badge 13
GDPR

Compliant

badge 13
ISO 27001

Certified

badge 13
HIPAA

Ready

badge 13
CCPA

Compliant

badge 13
PCI DSS

Level 1 Ready

Questions & Answers

Frequently asked questions

Tap any question to see how InsertChat would respond.

Contact support

InsertChat

AI Support

Hey! 👋 Browsing Security questions. Tap any to get instant answers.

Just now

Where is my data stored?

European servers. GDPR compliant, never used for training, and deletable at any time.

What is InsertChat, from a privacy standpoint?

An AI agent workspace that connects to your approved sources and uses model providers to generate responses. Privacy depends on what you ingest, what tools you enable, and who can access the agent.

What gets sent to AI model providers?

Your prompt and relevant context excerpts from connected sources are sent to the selected model provider to generate an answer.

Do you use our data to train models?

No. InsertChat never uses your data to train models.

Is my data isolated from other customers?

Yes. Data is scoped to your workspace and agents. Sources and conversations remain isolated.

Can I delete data?

Yes. Delete sources, conversation history, leads, and feedback at any time.

What data does InsertChat store?

Agent configuration, connected knowledge sources, and conversation data needed for the experience and analytics.

Can I keep an agent private?

Yes. Choose public or private agents depending on whether anyone or only authenticated users can access the embed.

Do you have role-based access controls?

Yes. Control who can manage agents and data with role-based access.

What is BYOK from a privacy standpoint?

You provide your own API key for model access. Prompts and context are still sent to the provider, so review their policies for your compliance needs.

Can I restrict what the agent can do?

Yes. Control tool enablement per agent to limit actions to only what is necessary.

Can we limit exposure of sensitive data in the agent?

Yes. Scope sources to what should be answerable and limit tool enablement to only what is required.

Can I export or audit what users asked?

Yes. Analytics show what people ask. Contact us for exports for audits or internal reporting.

Do you support GDPR?

Yes. Full GDPR compliance with Data Processing Addendum (DPA) available on request.

Can you provide a DPA?

Yes. Our DPA covers processing obligations, subprocessors, and deletion/return terms. Contact us to request it.

Do you list subprocessors?

Yes. Subprocessors are documented in the DPA. Request it or contact us for details.

How do you handle security questionnaires?

Contact us and we provide the right documentation for your team's review process.

Is InsertChat safe to embed on a public website?

Yes, when configured correctly. Ground answers in approved sources and keep tool access controlled.

What if we need a private deployment or special requirements?

Enterprise plans cover custom deployment, advanced controls, and procurement constraints. Contact us to discuss.

How do privacy requests work (access, deletion)?

Submit privacy requests through the contact page. We route them to the right process.

Where can I request security documentation?

Submit security inquiries through the contact page.

Do you support self-hosting?

Yes. Enterprise plans include self-hosting and bring-your-own-LLM options.

How do I evaluate InsertChat?

Start a free trial with non-sensitive data. When ready, request our security questionnaire and DPA.

0 of 23 questions explored Instant replies

Security FAQ

Where is my data stored?

European servers. GDPR compliant, never used for training, and deletable at any time.

What is InsertChat, from a privacy standpoint?

An AI agent workspace that connects to your approved sources and uses model providers to generate responses. Privacy depends on what you ingest, what tools you enable, and who can access the agent.

What gets sent to AI model providers?

Your prompt and relevant context excerpts from connected sources are sent to the selected model provider to generate an answer.

Do you use our data to train models?

No. InsertChat never uses your data to train models.

Is my data isolated from other customers?

Yes. Data is scoped to your workspace and agents. Sources and conversations remain isolated.

Can I delete data?

Yes. Delete sources, conversation history, leads, and feedback at any time.

What data does InsertChat store?

Agent configuration, connected knowledge sources, and conversation data needed for the experience and analytics.

Can I keep an agent private?

Yes. Choose public or private agents depending on whether anyone or only authenticated users can access the embed.

Do you have role-based access controls?

Yes. Control who can manage agents and data with role-based access.

What is BYOK from a privacy standpoint?

You provide your own API key for model access. Prompts and context are still sent to the provider, so review their policies for your compliance needs.

Can I restrict what the agent can do?

Yes. Control tool enablement per agent to limit actions to only what is necessary.

Can we limit exposure of sensitive data in the agent?

Yes. Scope sources to what should be answerable and limit tool enablement to only what is required.

Can I export or audit what users asked?

Yes. Analytics show what people ask. Contact us for exports for audits or internal reporting.

Do you support GDPR?

Yes. Full GDPR compliance with Data Processing Addendum (DPA) available on request.

Can you provide a DPA?

Yes. Our DPA covers processing obligations, subprocessors, and deletion/return terms. Contact us to request it.

Do you list subprocessors?

Yes. Subprocessors are documented in the DPA. Request it or contact us for details.

How do you handle security questionnaires?

Contact us and we provide the right documentation for your team's review process.

Is InsertChat safe to embed on a public website?

Yes, when configured correctly. Ground answers in approved sources and keep tool access controlled.

What if we need a private deployment or special requirements?

Enterprise plans cover custom deployment, advanced controls, and procurement constraints. Contact us to discuss.

How do privacy requests work (access, deletion)?

Submit privacy requests through the contact page. We route them to the right process.

Where can I request security documentation?

Submit security inquiries through the contact page.

Do you support self-hosting?

Yes. Enterprise plans include self-hosting and bring-your-own-LLM options.

How do I evaluate InsertChat?

Start a free trial with non-sensitive data. When ready, request our security questionnaire and DPA.