Our security commitments
We protect Customer Content and End User Personal Data with layered safeguards:
- Personal Data and Customer Content are encrypted in transit and at rest.
- Role-based access control (RBAC) governs who can see and do what, following the principle of least privilege.
- Scoped, per-conversation and per-Agent permissions mean an AI Agent can only access and act on what you allow.
- Activity and audit logging records actions taken in the Services, giving you a clear trail of what happened and why.
Infrastructure & hosting
The Services run on cloud infrastructure hosted in a data centre located in India. Physical, network, and platform security are managed by our hosting provider; we use hardened configurations, network controls, and regular patching. We intentionally keep infrastructure details high-level to avoid disclosing exploitable specifics.
Access controls
Access to the Services and to Customer data is restricted on a least-privilege basis:
- Role-based access control lets Customers assign roles and permissions to their team members.
- Single sign-on (SSO) and detailed audit logs are available on Enterprise plans for tighter governance.
- Multi-factor authentication (MFA) is not yet available and is planned for a future release.
- Internal administrative access by Mfluence personnel is limited to those who need it to operate and support the Services, and is logged.
AI Agent guardrails
AI Agents operate within boundaries you define. Every Agent action runs under scoped, per-conversation permissions and is recorded in an activity log. You decide which Tools and CRM actions each Agent may use, which actions require human confirmation, and when a conversation should escalate to a person. This keeps autonomy accountable — Agents only do what you have allowed, and you can review what they did.
Data isolation & multi-tenancy
Mfluence is a multi-tenant platform. Each Customer's data is logically separated so that one Customer cannot access another Customer's workspace, Content, or conversations. Access is enforced through authentication, authorisation, and tenant-scoping controls throughout the Services.
Data use & AI training
Your Knowledge Base and customer conversations belong to you and stay within your controlled workspace. Mfluence does not use Customer Content or End User Personal Data to train shared or public AI models. Because customer data stays within your workspace rather than being pasted into a public tool, you get the benefits of AI without giving up oversight of where sensitive information goes. For more on data handling, see our Privacy Policy.
Incident response
We maintain processes to detect, investigate, and respond to security incidents. In the event of a personal-data breach affecting your data, we will notify affected Customers without undue delay and, in any event, within 72 hours of becoming aware of the breach, and cooperate as required by applicable law and our agreements.
Compliance
We align our practices with widely recognised security principles. As this is an early-stage (MVP) launch, Mfluence does not currently hold a formal certification such as SOC 2 or ISO 27001. We intend to mature our security programme toward such standards over time.
Sub-processor security
We use vetted third-party sub-processors to deliver the Services (for example, cloud hosting, messaging channels, and AI model providers). We require sub-processors to maintain security standards appropriate to the data they handle and consistent with our commitments. The categories of sub-processors are described in our Privacy Policy.
Vulnerability disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability in the Services, please report it responsibly to security@mfluence.ai. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, and do not access, modify, or delete data that is not yours while testing.
Your responsibilities
Security is a shared responsibility. You are responsible for:
- Protecting your account credentials, API keys, and access tokens, and using SSO/MFA where available;
- Assigning roles and permissions appropriately and removing access when team members leave;
- Configuring which Tools, data, and actions your AI Agents may use; and
- Managing consent and opt-outs for your own End User communications, and complying with channel and privacy laws.
Contact
For security questions or to report an incident or vulnerability, contact security@mfluence.ai.