Skip to main content
Exerta is built on multiple independent layers of security, so your business data, customer conversations, and channel credentials are protected at every point. From encryption and access controls to compliance certifications and daily backups, every part of the platform is designed to keep your data safe — and to give you full visibility into who can see it and what they can do with it.

Data encryption

All data transmitted between your browser and Exerta’s servers is encrypted using TLS 1.3 — the current industry standard for data in transit. Data stored on Exerta’s infrastructure is encrypted using AES-256, the same standard used by banks and governments worldwide. Your social channel tokens and API credentials are stored in an encrypted, zero-knowledge credential vault. This means Exerta staff cannot read, export, or access your tokens under any circumstances. OAuth tokens are refreshed automatically so your connections stay live without you ever needing to re-authenticate.

Compliance

HIPAA compliance is available for healthcare and telehealth brands — contact the team to enable it on your account.

Access control

Exerta uses role-based access control (RBAC) with four built-in roles — Owner, Admin, Editor, and Viewer — ensuring that every team member has access only to what they need. A full audit log records every action taken in your workspace, including who made each change and when. Enterprise customers can request advanced access controls beyond the standard role set. For more detail on roles and permissions, see Team Access.

Infrastructure

Exerta runs on AWS with data centre locations in both the US and EU regions. The platform maintains a 99.9% uptime SLA on Scale and Enterprise plans. Automated daily backups are taken across all plans, with a 30-day retention period, so your data can be restored quickly in the event of any issue.

Your data and AI training

Exerta does NOT use your conversation data to train AI models. Your data is isolated per workspace and never shared with third parties.
Every workspace is fully isolated — your conversations, agent configurations, and customer data are never combined with data from other customers and are never used to improve or fine-tune any AI model. What happens in your workspace stays in your workspace.

Reporting a vulnerability

If you discover a security vulnerability in the Exerta platform, please report it to security@exerta.ai. Exerta acknowledges every report within 24 hours and works transparently with researchers to investigate and resolve issues. Exerta never takes legal action against researchers who report vulnerabilities in good faith.