GDPR
Privacy documentation + buyer diligence path
Read Privacy Policy; map lawful basis and data categories for your use case; request DPA language when required.
If you are evaluating FoundChat for AI customer support, start here. This overview explains how we think about protecting accounts, training content, and conversations and how you should run a practical vendor security review before you embed an agent on production pages.
Security for AI chatbots is not only encryption and hosting. It is also knowledge hygiene, escalation design, and clear ownership inside your company. Buyers who only ask for a SOC 2 logo miss the operating controls that prevent bad answers and data spills.
A simple path from approved knowledge to visitor answers and back into your weekly learning loop.
01
You connect websites, PDFs, docs, and Q&A. Only approved content should be indexed.
02
Tone, scope, and escalation rules define what the agent may answer vs hand off.
03
Website visitors ask questions in the widget; answers retrieve from your sources.
04
Conversations become quality signal. Humans review unanswered questions and update docs.
These pillars frame how FoundChat approaches AI chatbot data security. Use them as discussion prompts in your diligence call, then dig into the formal policy documents for legal language.
Limit production access based on operational need. Protect accounts with practical authentication and monitoring for suspicious activity. Workspace owners decide who can publish training sources and review transcripts.
Run on reputable hosting, database, AI, analytics, and payment providers. Keep dependencies and platform components updated where practical. Treat infrastructure as a living control not a one-time checkbox.
Training sources and conversation history exist to deliver the product. Treat docs, uploads, and chats as sensitive business data. Do not dump secrets into public help articles you plan to train on.
Billing is handled through established payment infrastructure so card data stays with the payment provider where applicable. FoundChat focuses on product usage data, not storing raw card numbers.
Exact vendors change. Ask for the current written list during procurement. Categories below describe the types of processors typically involved.
| Category | Typical use |
|---|---|
| Hosting / compute | Cloud application hosting for the product control plane and runtime |
| Database / storage | Managed databases and object storage for configs, sources metadata, and logs |
| AI model providers | Third-party model APIs you select per agent (provider set evolves) |
| Payments | Payment processor for subscription billing (card data stays with processor) |
| Email / transactional | Transactional email for product and billing notices |
| Analytics & ads (optional) | GA4, PostHog, Meta Pixel, Reddit Pixel when configured on foundchat.io |
We will not claim certifications we cannot produce on request. Treat the table as a diligence map not a badge wall.
GDPR
Privacy documentation + buyer diligence path
Read Privacy Policy; map lawful basis and data categories for your use case; request DPA language when required.
SOC 2
Confirm in writing for your deal
Do not treat marketing pages as a certification badge. Ask for current attestation status and report availability during procurement.
SSO / enterprise controls
Discuss on enterprise path
Identity and advanced controls are deal-specific. Start at /for/enterprise and book a demo for requirements.
Copy this checklist into your vendor review. It is designed for AI customer support and website chatbot evaluations not generic SaaS checklists that ignore training data and chat transcripts.
01
List training sources (websites, PDFs, Q&A), agent configuration, and conversation transcripts. Separately list what you will never put in training: secrets, raw card data, and regulated personal data you are not prepared to handle in chat.
02
Refunds, legal threats, security incidents, and VIP account changes should route to humans. Document those rules before go-live so the agent is not forced to improvise on money movement or liability topics.
03
Security is not only a vendor badge. Name who can publish training sources, who reviews transcripts weekly, and who responds if a conversation exposes sensitive data. Procurement will ask; have answers ready.
04
Ask which providers host data, where, and for how long. Confirm whether conversation data trains shared models. Keep written answers with your security questionnaire responses.
05
Ship the widget on limited pages with low-risk intents. Expand only after unanswered questions and escalation quality look healthy. A controlled pilot reduces both product and security risk.
06
Use this page as the buyer overview, then read the Security Policy and Privacy Policy for formal language. Enterprise teams should also review /for/enterprise for SSO and compliance messaging expectations.
Even strong vendors fail when customers skip process. Pair FoundChat with these internal habits so security and support quality move together.
Only people who need to train agents or review chats should have those permissions. Treat transcript access like ticket access useful for quality, sensitive by default.
Customers must be able to reach a human for exceptions. Design handoff so uncertain or sensitive topics do not become infinite AI loops.
Know who you email if something goes wrong, what logs you can pull, and how you will notify affected customers. Vague incident answers kill enterprise deals.
Printable-style answers for procurement. Pair with formal policies when legal review starts.
Website content and documents you connect for training, agent configuration, and customer conversations in the widget. Treat those materials as business-sensitive even when they are also public on your site.
Ask for the current written policy in your diligence packet. FoundChat’s product stance is to use your connected sources to answer your visitors not to treat your transcripts as a public training corpus. Confirm retention and model-training language in the Security Policy and a signed questionnaire response.
Hosting and databases run on reputable cloud infrastructure. Retention for chat logs depends on plan limits and your configuration. Request the current subprocessor and retention table during procurement lists change as vendors evolve.
FoundChat is GDPR-aware in product design and privacy documentation. Formal SOC 2 certification status should be confirmed in writing for your deal do not assume a logo from marketing copy. Use this page plus Security Policy and Privacy Policy, then send a vendor questionnaire covering subprocessors, retention, access, and training-use of conversation data.
The detailed Security Policy lives at /security-policy. This page is the buyer-facing overview for AI chatbot data security reviews, checklists, and diligence questions.
No. FoundChat is a website AI agent product. Enterprise buyers still need their own identity, retention, and vendor-risk processes. See /for/enterprise for how we frame security and procurement conversations.
Remove secrets and conflicting articles before training. Assign a knowledge owner. Review unanswered questions weekly so gaps become docs instead of hallucinated answers. Security and quality share the same hygiene habits.
Data categories processed, storage regions, retention, encryption in transit and at rest, access controls, subprocessors, incident response, and whether customer content is used to train shared models. Attach your escalation policy for chat.
You configure escalation rules for refunds, legal, security incidents, and VIP changes before go-live. Uncertain answers should hand off to humans not invent policy. Document those rules where your team can find them.
Workspace owners control who can publish training sources and review chats. Treat transcript access like ticket access useful for quality, sensitive by default. Least-privilege is an operating control, not only a vendor feature.
Know who you email if something goes wrong, what logs you can pull, and how affected customers are notified. Ask for the current incident contact path in diligence. Vague incident answers should pause an enterprise deal.
Billing runs through established payment infrastructure so raw card numbers stay with the payment provider where applicable. Do not put card data into training docs or expect the chat agent to process payments.
Keep exploring
Join founders using FoundChat for support, sales, onboarding, and lead capture.
No credit card required · Live in minutes · Cancel anytime.