Trust & Security Center
Last updated: August 2026
Sevenfold is built for businesses that handle real customer relationships and sensitive communications. Security and privacy are not features — they are the foundation everything else sits on. This page outlines the controls, certifications, and commitments we maintain to keep your data safe.
CASA Tier 2
Independently validated to Google’s security requirements
Sevenfold has successfully completed the Cloud Application Security Assessment (CASA) Tier 2, the independent security assessment required by Google for applications handling certain restricted Google user data.
Our assessment is conducted by TAC Security, an independent third-party laboratory authorised by the App Defense Alliance to perform CASA assessments.
What CASA checks
CASA reviews how Sevenfold protects your data, accounts and workspace across 48 applicable security controls, independently validated by the assessor.
Recognised security standard
CASA is operated by the App Defense Alliance and based on the OWASP Application Security Verification Standard (ASVS).
Independent validation
TAC Security issues a Letter of Validation confirming Sevenfold has met the applicable CASA Tier 2 requirements.
Compliance
Sevenfold operates in alignment with the following frameworks and regulations.
| Framework | Scope |
|---|---|
| Australian Privacy Act 1988 | Governing collection, use and disclosure of personal information in Australia |
| GDPR | EU data subjects — including EU Standard Contractual Clauses where applicable |
| CCPA / CPRA | California residents — operating as a compliant service provider |
| PCI DSS | Payment card data handled exclusively through Stripe, a Level 1 PCI DSS certified provider |
| Google API Limited Use | Compliance with Google’s API User Data Policy for any Google Workspace integrations |
Security Controls
Encryption All data in transit is encrypted using TLS 1.2 or higher. All data at rest is encrypted using AES-256. Encryption keys are managed separately from encrypted content and rotated on a regular schedule. OAuth tokens are encrypted independently from customer content.
Infrastructure Sevenfold uses an established cloud infrastructure platform that maintains SOC 2 Type II and SOC 3 compliance. Data is encrypted in transit and at rest, and Sevenfold applies application-level security controls to protect customer data. The underlying provider maintains physical security controls, 24/7 facility monitoring, and redundant power and connectivity across its data centres.
Workspace Isolation Every customer workspace is fully isolated at the application, database, and storage layers. Your data is inaccessible to other customers — there is no shared data environment across accounts.
Access Controls Internal access to Sevenfold systems follows least-privilege principles, enforced with multi-factor authentication across all team members. All access is logged and reviewed on a regular basis.
Monitoring Sevenfold systems are monitored continuously. Automated anomaly detection alerts our engineering and security teams to unusual activity. All system events are logged and retained for investigation purposes.
Penetration Testing We conduct annual third-party penetration testing across the full platform. Critical vulnerabilities are remediated within 24 hours of discovery. A testing summary is available on request.
AI and Data
| Commitment | Status |
|---|---|
| Customer data used to train Sevenfold models | Never |
| Customer data shared with third-party AI providers for training | Never |
| AI processing and generation providers | Anthropic, OpenAI, Google (Gemini, including Nano Banana) |
| Inference data used for model improvement by providers | Not permitted under our agreements |
| Customer approval required for outbound actions | Yes — configurable per workflow |
Your content, communications, configurations, and AI interaction records are never used to train or improve AI models. AI processing and image generation may be routed through Anthropic, OpenAI, and Google. When a Gemini model, including Nano Banana, is selected for image generation, Google processes the image prompt and any selected reference images to generate the requested image. These providers are not permitted to use submitted customer data for model training or improvement.
Subprocessors
All subprocessors are bound by confidentiality and data protection obligations consistent with our commitments to you.
| Provider | Purpose |
|---|---|
| Cloud infrastructure platform | Cloud infrastructure and hosting (SOC 2 Type II / SOC 3) |
| Anthropic | AI inference |
| OpenAI | AI inference and realtime voice models (GPT Realtime) |
| Google (Gemini API) | AI inference, image generation (including Nano Banana), and Gemini Live realtime voice |
| ElevenLabs | Text-to-speech for voice calls |
| Deepgram | Speech-to-text for voice calls |
| Cartesia | Text-to-speech for voice calls |
| Twilio | Telephony (voice call carriage and phone numbers) |
| Meta (WhatsApp Business Platform) | WhatsApp message transmission |
| Recall.ai | Meeting notetaker attendance, transcription, and meeting processing when enabled |
| Stripe | Payment processing (PCI DSS Level 1) |
| Zoho | CRM and customer support ticket management |
| Sentry | Error monitoring and diagnostics |
| Mixpanel | Product analytics |
| Plausible Analytics | Website visitor analytics (cookieless, EU-hosted, no personal data stored) |
For an up-to-date subprocessor list or to request advance notification of changes, contact privacy@sevenfoldai.com.
Data Retention and Deletion
| Event | Outcome |
|---|---|
| Active subscription | Data retained and accessible |
| Subscription cancelled | Data retained for 30 days for export or reinstatement |
| 30 days after cancellation | All data permanently deleted from systems and backups |
| Manual deletion request | Actioned within 7 business days |
Backups and Recovery
Sevenfold maintains regular onsite and offsite backups as part of a structured backup and recovery process designed to protect against data loss and support reliable service restoration.
Backup data and sensitive system configuration are protected using appropriate security controls, including encryption.
Incident Response
In the event of a confirmed security incident, we commit to notifying affected customers within 72 hours where required by applicable law, providing clear information about what happened, what data was affected, and the steps being taken. A post-incident report is available upon request.
Frequently Asked Questions
Where is my data stored? Customer data is stored with an established cloud infrastructure provider that maintains SOC 2 Type II and SOC 3 compliance. Data is encrypted in transit and at rest and protected with application-level security controls.
Is my data used to train AI models? No. Your data is never used to train or improve any AI model. This applies to all content, communications, and AI interaction records.
Is each customer’s data kept separate? Yes. Workspaces are fully isolated at the application, database, and storage layers. There is no shared data environment between customers.
What happens to my data when I cancel? Your data is retained for 30 days after cancellation for export or reinstatement, then permanently deleted from all systems and backups.
Can I request a copy of your security documentation? Yes. Contact security@sevenfoldai.com to request available security assessment documentation, a penetration test summary, or our subprocessor list.
How do you handle Google Workspace data? Where you authorise Sevenfold to connect to Google services, we access only the data required for the specific functions you enable. We comply with Google’s Limited Use requirements and do not use Google data for advertising or AI model development.
Reporting a Vulnerability
If you discover a potential security vulnerability in Sevenfold, please report it responsibly before public disclosure. We commit to acknowledging your report within 2 business days and will not pursue legal action against researchers acting in good faith.
Report to: security@sevenfoldai.com
Resources
Contact
For security-related queries, contact security@sevenfoldai.com