Security form, answered
These are the questions purchasing and security teams ask before they approve a vendor. They are answered here so no one waits two weeks for an email.
When the answer is "we do not have it", that is the real answer. Vendor reviews check facts, and a false claim costs more than the gap it tried to hide.
Access and identity
- How do our team members join the platform?
- With email and password, or with Google. Everyone gets their own login; the account is not shared.
- Is there corporate single sign-on (SAML SSO)?
- No. CertuAI does not offer SAML or automatic user provisioning via SCIM yet. Joining and leaving the team is done manually in the Dashboard by the account owner.
- Is there two-factor authentication?
- When you sign in with Google, your Google two-factor settings apply. CertuAI does not offer its own two-factor authentication for password login.
- Can you separate what each person sees and does?
- Partly. There is the account owner and invited members, and members cannot open Settings. There is no role system with screen-by-screen, field-by-field permissions today.
- How do we revoke access for someone who left?
- The owner removes the person in Dashboard and access ends right away. The log of actions they took stays saved.
Data
- Is the data kept in Brazil?
- Not all of it. The database and almost all processing run on servers in the United States (Google). Payment stays in Brazil (Asaas). The full list is on the security and data page.
- Is the data encrypted?
- In transit, yes: all traffic is HTTPS. At rest, standard Google Cloud and Cloudflare encryption applies. CertuAI does not add a second custom layer per field, and does not manage its own keys.
- Do you use our conversations to train models?
- No. Conversations only feed the support for the account itself.
- How long is data kept?
- For as long as the account exists. Deletion is done on request at [email protected].
- Can we take our data with us?
- Yes. Starting on the Max plan, authenticated HTTP export in NDJSON is available for your data team to pull on their schedule. It works with Snowflake, BigQuery, or custom scripts.
Auditing and content control
- Can we see who changed what the bot answers?
- Yes. Every change to the knowledge base logs who made it, when, the old value, and the new one. Each log has a digital signature so you can check later if it was changed.
- Is this record immutable?
- Not in the strict sense. The signature proves that the content of a record was not edited, but the storage does not stop someone with administrative access to the infrastructure from deleting an entire record. Storage that no one can delete is a service CertuAI has not bought yet.
- Can I require approval before a reply goes live?
- Yes, with setup. When turned on, changes go to a review queue and only go live after someone else publishes them. The person who suggested the change cannot approve it.
- How do we know the bot is not making up answers?
- There is a monthly report that samples answers and checks each against the account knowledge base, sorting them into backed, baseless, or contradictory. It is an automated screening: it cuts down what needs human review, but does not replace it.
- Can I keep conversation logs for compliance?
- Yes, if you set it up. Each record gets a digital signature, the team has to agree, and searches use the words the company chooses. Today the record identifies the account, not the individual employee who replied.
Certifications and stance
- Do you have ISO 27001 or SOC 2?
- No. CertuAI has no security certification issued by an outside company. The servers CertuAI uses (Google, Cloudflare) have their own certifications, and those do not carry over to CertuAI.
- Do you run periodic penetration tests?
- No penetration test by an outside firm has been done to date.
- Is there a formal incident response plan?
- There is no formal incident response document with agreed deadlines. Incident notices are sent by email to account owners.
- What is the uptime commitment?
- There is no service level agreement with uptime percentage or penalties in the standard offer. Contract uptime commitments are handled case by case.
- Who controls the data and who processes it?
- The client business owns its customers' data. CertuAI processes this data only to provide the service. See details at /seguranca.
- Do you sign a data processing agreement?
- Yes, subject to review. The document is handled during the negotiation at [email protected].
Missing a question?
Send the spreadsheet to [email protected]. Full details on data, vendors, and storage are on the page for security and data handling.