SECURITY & PRIVACY
Enterprise-grade
security
We take safety seriously. The world’s leading organizations trust us with their customer data, so we make it our business to keep it secure. Every inch of the Chattermill platform was built for peace of mind – from robust compliance to always-on data protection.
Chattermill was designed with multiple layers of built-in security to meet the world's highest standards in data protection and information security — with AI built to operate safely, inside your organization.
The enterprise standard for CX
Compliance
Independently verified and globally compliant, Chattermill handles data with the greatest level of care – giving enterprise teams one less thing to worry about.
SOC 2 Type II Certified
Chattermill is SOC 2 Type II certified – independently verifying our security, availability, and confidentiality controls.
ISO 27001 Certified
Certified to ISO 27001 — the international standard for information security management.
GDPR Compliance
Fully compliant with the General Data Protection Regulation (GDPR).
CCPA Compliance
Compliant with the California Consumer Privacy Act (CCPA), meeting US requirements for consumer privacy.
Privacy
Chattermill is SOC 2 Type II certified – independently verifying our security, availability, and confidentiality controls.
User Roles
Define user roles to control what each team member sees and does.
Single Sign-On (SSO)
Give your organization a single, secure way to manage platform access.
Data Permissions
Restrict data access at a granular level so sensitive information is only visible to authorized users.
Two-Factor Authentication (2FA)
Protect every user with two-factor authentication so every login stays secure.
PII Anonymization
Customer data is anonymized, so personally identifiable information (PII) is never exposed.
AI governance
Rigorously governed and continuously monitored, our use of AI — across the product and the organization — stays within clear boundaries.
Model Training
Customer data is only ever used to train that customer's own taxonomy — never shared with, or used to train models for, any other party.
Aligned with Global Standards
Our AI systems are governed in line with ISO 42001, the international standard for responsible AI management, and comply with the EU AI Act.
Responsible AI Policy
Chattermill maintains an AI security policy to ensure responsible AI practices across our organization.
AI Risk Assessments
AI risks — from unintended outputs to lack of transparency — are continuously identified and mitigated.
AI Impact Assessments
Our AI is assessed for its potential impact on individuals and society before deployment.
Lifecycle Management
Chattermill has full control over how AI models are designed, trained, tested, deployed, monitored, and retired.
The enterprise standard for CX




Security
Built to support enterprise-scale operations, security is embedded into every layer of Chattermill — from access controls to vulnerability testing, incident response, and disaster recovery.
Multi-Region Hosting
Customer data can be stored in the EU or the US, giving your organization full control over data residency.
Network Security Policy
Chattermill enforces strict network security controls to protect data and systems from unauthorized access.
Access Security
Access to production infrastructure is tightly controlled and fully traceable.
Physical Security
Infrastructure is hosted in facilities with strict physical access controls, continuous monitoring, and safeguards.
Incident Response
An Incident Response Plan tracks incidents from identification through resolution.
Risk Assessment
Formal risk assessments identify and evaluate threats to security, availability, and confidentiality.
Change Management
Development, staging, and production are strictly segregated, with all changes documented, tested, and approved before deployment.
Vulnerability Tests
Vulnerabilities are identified, patched, and validated through annual third-party penetration testing.
Organizational Management
Security is embedded across the organization — through defined roles, mandatory training, screened hires, and regular management oversight.
Confidentiality
Data is classified, retained, and disposed of per compliance and contractual requirements.
Availability
Systems are built for high availability, with automated backups, regular disaster recovery testing, and continuous uptime monitoring.
Communications
Terms of Service, Privacy Policy, and security commitments are published and accessible to all Chattermill customers.
CX intelligence.
Built for enterprise.
Frequently asked questions
What compliance certifications does Chattermill hold?
We’re SOC 2 Type II and ISO 27001 certified. We’re also fully committed to GDPR and CCPA compliance.
Request our full documentation at trust.chattermill.com.
Does Chattermill support role-based access controls?
Yes. Chattermill's user management supports custom roles — including Reader-only, Admin, and others — with access configured to your business needs, such as permissions by department, region, or product.
How does Chattermill handle PII redaction?
Chattermill automatically redacts PII from customer feedback at the point of ingestion — before it’s stored or processed.
This includes common formats like email addresses, phone numbers, credit card numbers, and social security numbers, along with custom formats defined by your organization.
Once redacted, the information is permanently replaced and can’t be recovered.
Does Chattermill use my customer data to train its AI models?
Customer data is used exclusively to train the bespoke taxonomy for your organization — trained in isolation, with no crossover into any other client's model.
Training draws on historical data and is limited to verbatim response text. No PII — customer identifiers, contact details, or other personal fields — enters the training pipeline.
The resulting model is exclusive to your organization.
Where will our data be processed and stored?
The Chattermill platform is hosted on Google Cloud Platform, with UK/EU data residency as standard, and full support for US data residency if preferred.
How does Chattermill manage third-party subprocessors?
We carefully vet all third-party subprocessors to ensure they meet our strict security and compliance standards. Request a full list of all our subprocessors at trust.chattermill.com.

