Security
Last updated: July 28, 2026
Security is built into every layer of SellPilot AI. This page summarizes the practices in place today across encryption, authentication, infrastructure, and incident response.
Encryption
All client and server traffic uses TLS in transit. Sensitive data including channel access tokens is encrypted at rest.
Authentication
Accounts are protected with strong password requirements and optional two-factor authentication. Super-administrator accounts require two-factor authentication.
Role-Based Access
Workspace membership is governed by least-privilege roles. Sensitive actions require elevated permissions and are recorded in an audit log.
Audit Logs
Privileged actions, configuration changes, and security-relevant events are captured in an audit log available to Workspace owners.
Infrastructure Monitoring
We continuously monitor availability, latency, error rates, and security signals. Alerts are routed to on-call engineers.
Incident Response
We follow a documented incident-response process covering detection, containment, eradication, recovery, and post-incident review. Affected customers are notified in line with applicable obligations.
Regular Security Updates
Dependencies, runtimes, and infrastructure components are reviewed and updated regularly. Security-relevant patches are prioritized.
Backups
Production data is backed up regularly with integrity verification. Backup-restoration procedures are tested periodically.
High Availability
The Platform is deployed on managed infrastructure that supports redundancy and rapid recovery from regional or component failures.
Responsible Disclosure
If you believe you have discovered a security vulnerability, please email privacy@sellpilothub.com with details and proof-of-concept. We acknowledge reports promptly and work in good faith to remediate confirmed issues.
Certifications
SellPilot does not currently claim ISO, SOC 2, or PCI certifications. We focus on transparent, verifiable practices and continuously improve our security posture.