Your data security is our highest priority. ChatMox is SOC 2 Type II certified, GDPR compliant, and built with security best practices at every layer.
All stored data is encrypted using AES-256. Database backups are independently encrypted with separate keys.
All traffic uses TLS 1.3. HSTS is enforced across all ChatMox domains. Insecure connections are rejected.
Every customer's data is logically isolated. Tenant IDs are enforced at the database query level on every request.
Least-privilege access for all employees. Customer data access requires explicit approval and is fully logged.
Automated security monitoring detects and alerts on anomalous API activity, brute force attempts, and data exfiltration.
We engage independent third-party security firms to perform annual penetration testing of our infrastructure.
Your knowledge base and conversation data is NEVER used to train AI models. It's processed in isolated inference calls only.
Cloudflare enterprise DDoS protection with automatic mitigation. Our services remain operational even under heavy attacks.
SOC 2 Type II
Certified 2025
GDPR
Compliant
CCPA
Compliant
ISO 27001
In Progress
We take security reports seriously and aim to respond within 24 hours. If you discover a security issue, please email us rather than posting it publicly.
Submit a security reportWe offer a responsible disclosure program with bounties for qualifying vulnerabilities.