> ## Documentation Index
> Fetch the complete documentation index at: https://docs.exerta.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Exerta Security, Encryption, and Compliance Overview

> Exerta protects your data with TLS 1.3 encryption, AES-256 at rest, a zero-knowledge credential vault, and GDPR and ISO 27001 compliance.

Exerta is built on multiple independent layers of security, so your business data, customer conversations, and channel credentials are protected at every point. From encryption and access controls to compliance certifications and daily backups, every part of the platform is designed to keep your data safe — and to give you full visibility into who can see it and what they can do with it.

## Data encryption

All data transmitted between your browser and Exerta's servers is encrypted using **TLS 1.3** — the current industry standard for data in transit. Data stored on Exerta's infrastructure is encrypted using **AES-256**, the same standard used by banks and governments worldwide.

Your social channel tokens and API credentials are stored in an **encrypted, zero-knowledge credential vault**. This means Exerta staff cannot read, export, or access your tokens under any circumstances. OAuth tokens are refreshed automatically so your connections stay live without you ever needing to re-authenticate.

## Compliance

| Standard          | Status                              |
| ----------------- | ----------------------------------- |
| **GDPR**          | Compliant                           |
| **ISO 27001**     | Compliant                           |
| **SOC 2 Type II** | Audit in progress                   |
| **HIPAA**         | Available on Scale/Enterprise plans |

<Tip>
  HIPAA compliance is available for healthcare and telehealth brands — contact the team to enable it on your account.
</Tip>

## Access control

Exerta uses **role-based access control (RBAC)** with four built-in roles — Owner, Admin, Editor, and Viewer — ensuring that every team member has access only to what they need. A full **audit log** records every action taken in your workspace, including who made each change and when. Enterprise customers can request advanced access controls beyond the standard role set.

For more detail on roles and permissions, see [Team Access](/account/team-access).

## Infrastructure

Exerta runs on **AWS** with data centre locations in both the **US and EU regions**. The platform maintains a **99.9% uptime SLA** on Scale and Enterprise plans. Automated daily backups are taken across all plans, with a **30-day retention period**, so your data can be restored quickly in the event of any issue.

## Your data and AI training

<Note>
  Exerta does **NOT** use your conversation data to train AI models. Your data is isolated per workspace and never shared with third parties.
</Note>

Every workspace is fully isolated — your conversations, agent configurations, and customer data are never combined with data from other customers and are never used to improve or fine-tune any AI model. What happens in your workspace stays in your workspace.

## Reporting a vulnerability

If you discover a security vulnerability in the Exerta platform, please report it to **[security@exerta.ai](mailto:security@exerta.ai)**. Exerta acknowledges every report within **24 hours** and works transparently with researchers to investigate and resolve issues. Exerta never takes legal action against researchers who report vulnerabilities in good faith.


## Related topics

- [Exerta FAQ: Answers to Common Questions About the Platform](/account/faq.md)
- [AI Agents Overview: How Exerta Automates Engagement](/agents/overview.md)
- [Exerta Pricing: Plans, Credits, and Billing Details](/account/plans-and-billing.md)
- [Managing Team Access and Roles in Your Exerta Workspace](/account/team-access.md)
- [Get Started with Exerta: Live AI Agents in 5 Minutes](/quickstart.md)
