Security and Privacy
What happens to your data, who can see it, how long it is kept, and the compliance standards eesel meets.
What happens to your data, who can see it, and the compliance standards we meet. If your questions aren't answered here, contact us and we'll work with your security team directly.
Resources
Compliance
Storing and processing data
Your knowledge sources are securely stored in a SOC 2 Type II certified vector database as embeddings (mathematical representations). These embeddings are what allow your agent to find relevant answers.
When a request is made, the agent uses embeddings to find related content and shares only specific relevant snippets with the AI model to generate a response.
Your data is used only to train your agent and generate responses
Your data is never used to train our underlying AI models
Data is isolated per workspace, your content is never shared with other customers
EU Data Residency
EU data residency is available upon request, your data will be hosted exclusively on EU servers. Our subprocessors (including OpenAI and Pinecone) are SOC 2 Type II certified for data security.
Contact us if you want to be hosted on EU servers.
Data retention
Your data is retained as long as your account is active
When you disconnect an integration or delete knowledge sources, the associated data is removed
When you cancel, your data is removed after your account is closed out
Custom retention arrangements are available on our Enterprise plan. If you have specific retention, residency or deletion requirements, get in touch and we'll work through them with you. See Pricing.
Encryption
Data is encrypted in transit (TLS 1.2+)
Data is encrypted at rest
API tokens and credentials are stored using industry-standard secret management
Access control
Authentication via secure login (MFA available, contact us to enable)
Role-based access control for team members (see Account Management)
API access is scoped per integration, we request only the permissions we need
AI model security
eesel AI uses leading AI models (OpenAI, Anthropic, Google) to power agents
Your data is sent to these model providers only for inference (generating responses)
No model provider stores or trains on your data
The AI model never sees your credentials. Where an agent calls a connected tool or an API you've allowed, the request is made by eesel and the authentication is attached server-side, so the model knows a header exists but never its value
We maintain agreements with all AI model providers to ensure data protection
FAQ
Questions?
If you have security or compliance questions, or need a security questionnaire completed, start a conversation in the support chat under Help and support in your dashboard, or email hi@eesel.app.
We're happy to work with your security team on assessments and provide whatever documentation you need.
Last updated