Security and privacy
Your data, your credits, your liability
Three questions come up before anyone trusts an AI agent with real customers: where does my data go, what stops bots draining my credits, and what happens if the agent says something wrong. This page is maintained by the Echo AI team and describes controls available in the product today. It is not an independent audit or a certification. Security contact: support@echoai.so
Where your data lives and how it is used
- Knowledge, documents, catalogue and conversations stored in your own workspace on managed Postgres, isolated per account with row level security
- HTTPS and TLS in transit, with integration tokens and payment credentials handled server side only
- Your conversations are never used to train external models
- Optional anonymisation replaces emails and phone numbers with placeholders before a message reaches the model, plus data minimisation that strips metadata
- Automatic conversation deletion with a retention period you set in days
- One click JSON export of Echos, conversations, contacts and settings
- Deleting your account hard deletes Echos, conversations, documents, contacts and integration tokens
Bots, spam and your credit balance
- Rate limits per IP address and per session on chat, with separate limits on other visitor facing endpoints
- Configurable spam threshold and cooldown for rapid message bursts
- IP bans, word filters, profanity filtering and automatic link moderation per Echo
- Password protected Echo pages, unlisted Echos and internal knowledge mode
- Itemised credit history, low balance alerts and weekly reports
What your Echo is allowed to say
- Answers grounded in the knowledge, documents, catalogue and policies you provide
- Pre-filter escalates refunds, chargebacks, legal action, medical and health advice, allergies, emergencies, complaints and data requests to a human, in several languages
- Jailbreak and prompt injection filtering, plus disclosure modes
- Instant pause and human takeover on any channel
- Full transcripts with channel and timestamp for review
Account and access security
- Passkeys with Face ID, Touch ID or a hardware key, and app based two factor authentication
- API keys, OAuth tokens and payment secrets kept in server side secret storage
- Roles stored separately from profiles and checked server side
- Baskets, orders and visitor sessions scoped by session token
Compliance status
- In place: GDPR aligned practices, cookie consent with granular choices, self serve export and deletion, row level security, documented subprocessors on request
- Working towards: SOC 2 Type II readiness and ISO 27001 aligned information security management
- Echo AI does not currently hold SOC 2 Type II or ISO 27001 certification, and nothing on this page is an audit report or a legal guarantee
- For a security questionnaire, a DPA or subprocessor details, email support@echoai.so
Frequently asked questions
Do you train AI models on my conversations?
No. Your knowledge and conversations are used to answer your visitors and to produce your own analytics. They are not used to train external models.
What happens to my data if I close my account?
It is deleted. Closing the account removes your Echos, conversations, documents, contacts and integration tokens. There is no dormant copy waiting to be reactivated.
Can a bot drain my credits?
That is what the rate limits, spam thresholds, IP bans and link filters are for. Automated floods are rejected before the model runs, so they do not consume credits. Credit history shows every action, and low balance alerts warn you early.
What if my Echo says something wrong or legally risky?
Answers are grounded in the material you provide, and a pre-filter escalates refund, legal, medical and complaint topics to a human instead of answering. You can pause the Echo instantly, review the full transcript and fix the knowledge behind it. The agent speaks for your business, so the guardrails are yours to configure.
Are you GDPR compliant?
We follow GDPR aligned practices, including cookie consent, data minimisation options, PII anonymisation and self serve export and deletion. Compliance also depends on how you use the platform. For a DPA or a security questionnaire, contact support@echoai.so.
Do you have SOC 2 or ISO 27001?
Not yet. We are building towards SOC 2 Type II readiness and ISO 27001 aligned practices, and we will publish the status here when that changes.