Security

Your data is safe
by design

Security is not an afterthought at Eutexa. Every layer of our platform is built with enterprise-grade protection, from encryption and access controls to infrastructure hardening and compliance.

Our practices

How we protect your data

Encryption at rest and in transit

All data is encrypted at rest with AES-256 and in transit over TLS. Sensitive credentials such as integration API keys and OAuth tokens get an extra layer of AES-256-GCM encryption at the application level before they ever touch the database.

Authentication and access control

Sign in with email and password, with Google, or with Microsoft. Role-based permissions across super administrator, admin, and member, plus per-user permission overrides, let you control exactly who can view, edit, or delete contacts, deals, and reports.

Infrastructure security

Hosted on Google Cloud. Inherits Google Cloud's automatic DDoS mitigation at the network edge, hardened network isolation, and the patching cadence Google maintains on the underlying compute fleet.

Audit logging

Every workspace action across auth, integrations, contacts, deals, sequences, workflows, calls, meetings, and AI actions is logged with timestamp, actor identity, and IP address. Standard plans retain logs for 12 months. Enterprise workspaces retain indefinitely.

Workspace isolation

Every record belongs to exactly one workspace. Every database query is scoped by workspace ID at the framework level, so customer data is never returned across workspace boundaries even by a misconfigured request.

Your data does not train AI models

Eutexa's AI runs on Google Cloud Vertex AI, under terms that prohibit Google from using customer content to train or fine-tune its models. Your contacts, emails, calls, and transcripts are processed to answer the request in front of you and are not retained by the model provider afterwards.

Compliance posture

Every certification Eutexa relies on is listed below with the provider that holds it and a link to their trust center. A Eutexa-owned SOC 2 program and independent third-party penetration testing are on the roadmap and will be published as we complete them.

Certifications and standards

What we run on, and who certifies it

Eutexa does not hold an audit of its own yet, so each certification below names the provider that carries it, with a link to the trust center where you can pull the report yourself rather than take our word for it.

SOC 2 Type II
Held by Google Cloud, MongoDB Atlas, Vercel

Every tier Eutexa runs on is audited annually to SOC 2 Type II: Google Cloud for compute and AI, MongoDB Atlas for the database, Vercel for the web tier. A Eutexa-owned SOC 2 program is on the roadmap and will be published when it completes. Google Cloud compliance reports

ISO/IEC 27001
Held by Google Cloud, MongoDB Atlas, Vercel

The data centers that hold your workspace are certified to ISO/IEC 27001, the international standard for managing information security. The certificates are published by each provider. MongoDB Atlas trust center

PCI DSS Level 1
Held by Razorpay

Card details are entered directly into a PCI DSS Level 1 payment provider and never reach a Eutexa server. We store no card numbers, and there is no card data in our database to breach. Razorpay security

AES-256 and TLS
Held by Eutexa

Data is encrypted at rest with AES-256 and in transit over TLS. Integration API keys and OAuth tokens get a second layer of AES-256-GCM encryption in the application before they are written to the database, so a database copy alone does not yield a working credential.

Eutexa does not sign Business Associate Agreements and is not a HIPAA-covered platform, so protected health information should not be stored in a workspace. GDPR and CCPA data processing terms are in progress and are not yet offered as a signed agreement.

Responsible disclosure

Found a vulnerability? We appreciate responsible disclosure. Please email our security team and we will respond within 48 hours.

security@eutexa.com