Skip to main content
Exerta is built on multiple independent layers of security, so your business data, customer conversations, and channel credentials are protected at every point. From encryption and access controls to compliance certifications and AI data isolation, every part of the platform is designed to keep your data safe — and to give you full visibility into who can see it and what they can do with it.

Data encryption

All data transmitted between your browser and Exerta’s servers is encrypted using TLS 1.3 — the current industry standard for data in transit. Data stored on Exerta’s infrastructure is encrypted using AES-256, the same standard used by banks and governments worldwide. Your social channel tokens and API credentials are stored in an isolated per-workspace credential vault with zero-knowledge storage. Exerta staff cannot read, export, or access your tokens under any circumstances. OAuth tokens are refreshed automatically so your connections stay live without you ever needing to re-authenticate.

Compliance

SOC 2 Type II certification is not yet held — the audit is currently in progress.
HIPAA compliance is available exclusively on Enterprise plans and requires a signed Business Associate Agreement (BAA). Contact the team to enable it on your account.

Access control

Exerta uses role-based access control (RBAC) with four built-in roles — Owner, Admin, Editor, and Viewer — ensuring that every team member has access only to what they need. For more detail on roles and permissions, see Team Access.

Your data and AI training

Exerta does NOT use your conversation data to train AI models. Your data is isolated per workspace and never shared with third parties or used to improve any third-party model.
Every workspace is fully isolated — your conversations, agent configurations, and customer data are never combined with data from other customers and are never used to fine-tune any AI model. What happens in your workspace stays in your workspace.

Reporting a vulnerability

If you discover a security vulnerability in the Exerta platform, please report it to security@exerta.ai. Exerta acknowledges every report within 24 hours and works transparently with researchers to investigate and resolve issues. Exerta never takes legal action against researchers who report vulnerabilities in good faith.