Trust

Security

Effective Date: June 12, 2026

Security at a glance

  • AgentReception AI is designed to protect business and customer communication data.
  • We separate customer workspace data from platform operations and internal admin tools.
  • We use trusted infrastructure and service providers to operate the platform.
  • Access to accounts and workspaces should be controlled by authorized users only.
  • We do not claim SOC 2, HIPAA, or similar certification unless formally achieved and published.
  • SMS, voice, WhatsApp, calendar, and AI-assisted sending may be disabled until channel setup and approval are complete.
  • Live subscription billing and checkout may be unavailable until separately enabled for your account.
  • No online system can be guaranteed 100% secure.

Our security approach

AgentReception AI follows practical security principles designed for a small-business SaaS platform. Our approach is to understand what data the service handles, limit unnecessary access, protect data in transit and at rest where appropriate, monitor reliability and abuse signals, plan for incidents, and keep provider integrations controlled.

  • Know what business, customer, and operational data the platform processes.
  • Limit access to the minimum needed to operate and support the service.
  • Use reasonable safeguards for stored and transmitted data.
  • Monitor for reliability issues, failed jobs, and abuse signals where available.
  • Prepare to investigate and respond to suspected security issues.
  • Keep third-party integrations scoped to the features they support.

Data we protect

Depending on how a business uses AgentReception AI, the platform may handle:

  • Business account and profile data
  • Customer and lead information
  • Conversations, inbox messages, and follow-up records
  • Call summaries, transcripts, and call metadata if voice features are enabled
  • Appointment and calendar data
  • SMS and WhatsApp records
  • Billing and subscription records
  • Usage, log, and diagnostic data
  • Consent and opt-out records

For more detail on collection and use, see our Privacy Policy.

Workspace separation

  • Each business workspace should only access its own leads, conversations, appointments, channels, usage, billing, and settings.
  • Internal admin views are separate from normal customer dashboard views.
  • Technical provider and debug information should not appear in standard customer dashboards.
  • Future Supabase Row Level Security and related tenant controls are intended to enforce workspace isolation at the data layer.

Account and access security

  • Business owners should invite only trusted staff into a workspace.
  • Users should use strong passwords and protect login credentials.
  • Access should be removed when staff leave or no longer need workspace access.
  • Role-based access may be used to limit what staff can view or change.
  • AgentReception AI will continue improving account security as the platform matures.

Multi-factor authentication and single sign-on may be offered in the future, but are not represented here as currently available unless explicitly enabled in the product.

Provider and integration security

AgentReception AI may rely on providers such as:

  • Supabase for authentication and database services
  • Twilio for SMS, voice, and WhatsApp
  • Stripe for payments and subscription billing
  • Resend for transactional email notifications
  • Google Calendar for calendar sync when connected
  • AI providers for AI-assisted features

Connected services may require OAuth, API keys, tokens, or other credentials. Access should be limited to what is needed for the connected feature, and businesses can disconnect supported integrations where account or provider controls allow.

Provider integrations may remain disabled until a business completes setup, credentials are configured, and any required provider or carrier approval is in place. AgentReception AI does not send live SMS, voice, WhatsApp, email, calendar sync, or customer-facing AI messages through those providers when related features or account controls keep them off.

Messaging and voice security

  • SMS, calls, and WhatsApp features should be used for customer-care and appointment workflows when enabled for a workspace.
  • SMS, voice, and WhatsApp sending may be disabled until channel setup, provider approval, and account enablement are complete.
  • Consent and opt-out records may be stored for compliance, audit, and provider requirements.
  • Voice features may create call summaries, transcripts, or metadata when enabled.
  • Businesses are responsible for call recording or transcription notices where required by law.
  • Providers and carriers may filter, delay, reject, suspend, or block messages or calls for security or compliance reasons.

Calendar and connected services

If Google Calendar is connected, AgentReception AI may access calendar data needed for appointment workflow, such as creating, updating, syncing, and displaying appointment events. Calendar sync is not active for every account until the business connects Google Calendar and the integration is enabled.

  • Calendar data should be used for scheduling and appointment-related operations.
  • Google Calendar is a connected service, not the only source of truth for a business schedule.
  • Disconnecting Google Calendar may affect sync, reminders, or appointment workflows.

The scope of Google Calendar data access depends on the permissions granted at connection time and the appointment features enabled in the workspace. Final provider and product settings should be confirmed before broad production rollout.

Billing security

When live billing is enabled for an account, payments are processed by Stripe. AgentReception AI should not store full payment card numbers directly. We may store billing status, invoices, plan details, subscription state, and limited payment metadata needed for account management.

Checkout, subscription changes, and billing portal access may be disabled during test mode, controlled rollout, or maintenance. When disabled, no live payment data is collected through checkout flows in the Service.

AI security considerations

  • AI may use business-provided data and conversation context to generate replies, summaries, classifications, and next-step suggestions.
  • Businesses should avoid adding unnecessary sensitive data to AI training content or workspace settings.
  • AI output should be reviewed before sending sensitive, regulated, or high-value messages.
  • Whether AI provider data is used for model training or other secondary purposes depends on the applicable provider settings and contractual terms in place at the time.
  • AI-assisted replies or customer-facing sends may be limited or disabled until AI providers are connected and the related feature is enabled for the workspace.

Monitoring and reliability

Internal admin views may show system health, failed jobs, failed messages, failed calls, failed syncs, and billing issues. This operational monitoring is separate from normal customer dashboard data.

  • We do not guarantee uninterrupted uptime.
  • We do not guarantee that every message, call, sync, or workflow will succeed.
  • Provider outages, API changes, or network issues may affect service reliability.

Incident response

If a security issue is suspected, AgentReception AI may investigate, limit access, rotate credentials, disable affected features, notify affected users where appropriate, and work with providers as needed.

Exact investigation steps, timelines, and legal notices may depend on the situation, severity, and applicable law. Our formal incident response runbook, escalation paths, and breach notification procedures are being finalized and may be updated as the platform matures.

Data retention and deletion

Data retention and deletion practices vary by data type, account status, legal requirements, and product capabilities. Retention schedules, automated deletion workflows, and self-service export or deletion tools are being finalized.

For current high-level retention descriptions, see our Privacy Policy. For privacy or deletion requests, contact privacy@agentreceptionai.com.

Customer responsibilities

Businesses using AgentReception AI are responsible for:

  • Keeping business settings accurate and up to date
  • Sending lawful customer communications
  • Controlling staff access to workspaces
  • Protecting login credentials and workspace access
  • Not sharing secrets, API keys, or passwords insecurely
  • Reviewing AI output when messages are sensitive or high-impact
  • Honoring privacy and messaging requests where applicable
  • Using connected accounts and integrations responsibly

Security limitations

  • No system is 100% secure.
  • AgentReception AI does not currently claim SOC 2 certification.
  • AgentReception AI does not currently claim HIPAA compliance.
  • AgentReception AI does not currently claim ISO 27001 or similar certification.
  • Security features and controls will continue improving as the product matures.

Reporting security concerns

If you believe you have found a security issue affecting AgentReception AI, contact security@agentreceptionai.com.

Please include, when possible:

  • A clear description of the issue
  • The affected page, feature, or workflow
  • Steps to reproduce, if applicable
  • Screenshots or logs only if they are safe to share
  • Your contact information

Do not include passwords, full API keys, or other secrets in your report. We do not currently offer a public bug bounty program unless separately announced.

Contact

Legal and security review notice

This Security page is a business-ready draft and should be reviewed before production launch.

© 2026 AgentReception AI. All rights reserved.

This Security page draft is original to AgentReception AI and may not be copied or reused without permission.