SECURITY & PRIVACY

Enterprise-grade
security

Visit our trust center

We take safety seriously. The world’s leading organizations trust us with their customer data, so we make it our business to keep it secure. Every inch of the Chattermill platform was built for peace of mind – from robust compliance to always-on data protection.

Chattermill was designed with multiple layers of built-in security to meet the world's highest standards in data protection and information security — with AI built to operate safely, inside your organization.

The enterprise standard for CX

Compliance

Independently verified and globally compliant, Chattermill handles data with the greatest level of care – giving enterprise teams one less thing to worry about.

SOC 2 Type II

SOC 2 Type II Certified

Chattermill is SOC 2 Type II certified – independently verifying our security, availability, and confidentiality controls.

ISO 27001

ISO 27001 Certified

Certified to ISO 27001 — the international standard for information security management.

GDPR

GDPR Compliance

Fully compliant with the General Data Protection Regulation (GDPR).

CCPA

CCPA Compliance

Compliant with the California Consumer Privacy Act (CCPA), meeting US requirements for consumer privacy.

Privacy

Chattermill is SOC 2 Type II certified – independently verifying our security, availability, and confidentiality controls.

User Roles

User Roles

Define user roles to control what each team member sees and does.

SSO

Single Sign-On (SSO)

Give your organization a single, secure way to manage platform access.

Data Permissions

Data Permissions

Restrict data access at a granular level so sensitive information is only visible to authorized users.

2FA

Two-Factor Authentication (2FA)

Protect every user with two-factor authentication so every login stays secure.

PII Anonymization

PII Anonymization

Customer data is anonymized, so personally identifiable information (PII) is never exposed.

AI governance

Rigorously governed and continuously monitored, our use of AI — across the product and the organization — stays within clear boundaries.

Model Training

Model Training

Customer data is only ever used to train that customer's own taxonomy — never shared with, or used to train models for, any other party.

ISO 42001

Aligned with Global Standards

Our AI systems are governed in line with ISO 42001, the international standard for responsible AI management, and comply with the EU AI Act.

Responsible AI Policy

Responsible AI Policy

Chattermill maintains an AI security policy to ensure responsible AI practices across our organization.

AI Risk Assessments

AI Risk Assessments

AI risks — from unintended outputs to lack of transparency — are continuously identified and mitigated.

AI Impact Assessments

AI Impact Assessments

Our AI is assessed for its potential impact on individuals and society before deployment.

Lifecycle Management

Lifecycle Management

Chattermill has full control over how AI models are designed, trained, tested, deployed, monitored, and retired.

The enterprise standard for CX

Security

Built to support enterprise-scale operations, security is embedded into every layer of Chattermill — from access controls to vulnerability testing, incident response, and disaster recovery.

Multi-Region Hosting

Multi-Region Hosting

Customer data can be stored in the EU or the US, giving your organization full control over data residency.

Network Security Policy

Network Security Policy

Chattermill enforces strict network security controls to protect data and systems from unauthorized access.

Access Security

Access Security

Access to production infrastructure is tightly controlled and fully traceable.

Physical Security

Physical Security

Infrastructure is hosted in facilities with strict physical access controls, continuous monitoring, and safeguards.

Incident Response

Incident Response

An Incident Response Plan tracks incidents from identification through resolution.

Risk Assessment

Risk Assessment

Formal risk assessments identify and evaluate threats to security, availability, and confidentiality.

Change Management

Change Management

Development, staging, and production are strictly segregated, with all changes documented, tested, and approved before deployment.

Vulnerability Tests

Vulnerability Tests

Vulnerabilities are identified, patched, and validated through annual third-party penetration testing.

Organizational Management

Organizational Management

Security is embedded across the organization — through defined roles, mandatory training, screened hires, and regular management oversight.

Confidentiality

Confidentiality

Data is classified, retained, and disposed of per compliance and contractual requirements.

Availability

Availability

Systems are built for high availability, with automated backups, regular disaster recovery testing, and continuous uptime monitoring.

Communications

Communications

Terms of Service, Privacy Policy, and security commitments are published and accessible to all Chattermill customers.

“Initially, our collaboration with Chattermill started as a focused NPS partnership, providing valuable insights into our consumer base. Over the past seven years, Chattermill has evolved into a critical global partner, supporting us with data across both mobility and delivery, and covering all five mega-regions in which we operate.”

Renata Vasconcellos de Sa

Head of Rider

See more customer stories

CX intelligence.
Built for enterprise.

Book a demo

Frequently asked questions

What compliance certifications does Chattermill hold? 

We’re SOC 2 Type II and ISO 27001 certified. We’re also fully committed to GDPR and CCPA compliance.

Request our full documentation at trust.chattermill.com.  

Does Chattermill support role-based access controls?

Yes. Chattermill's user management supports custom roles — including Reader-only, Admin, and others — with access configured to your business needs, such as permissions by department, region, or product.

How does Chattermill handle PII redaction?

Chattermill automatically redacts PII from customer feedback at the point of ingestion — before it’s stored or processed.

This includes common formats like email addresses, phone numbers, credit card numbers, and social security numbers, along with custom formats defined by your organization.

Once redacted, the information is permanently replaced and can’t be recovered.

Does Chattermill use my customer data to train its AI models?

Customer data is used exclusively to train the bespoke taxonomy for your organization — trained in isolation, with no crossover into any other client's model.

Training draws on historical data and is limited to verbatim response text. No PII — customer identifiers, contact details, or other personal fields — enters the training pipeline.

The resulting model is exclusive to your organization.

Where will our data be processed and stored?

The Chattermill platform is hosted on Google Cloud Platform, with UK/EU data residency as standard, and full support for US data residency if preferred.

How does Chattermill manage third-party subprocessors?

We carefully vet all third-party subprocessors to ensure they meet our strict security and compliance standards. Request a full list of all our subprocessors at trust.chattermill.com.