Independently audited. Report available to customers under NDA.
TLS in transit. AES-256 at rest. Keys we can rotate.
Enterprise maps your identity provider and groups.
Desk actions, admin changes, exports — available to owners.
Local hours in every market you operate. Private region on Enterprise.
High-risk actions wait for a person before they ship.
Posture
Fless is an AI workforce platform. Customers put briefs, knowledge, and sometimes recordings into desks. We treat that as production customer data: least privilege, encryption, logging, and a path for your security team to review us.
We design so a compromised seat does not equal the whole company: roles, workspace isolation, and optional SSO on Enterprise.
Product controls
Workspace owners turn desks on and off. Admins invite people and set who can publish, export, or connect tools. Activity from marketing, voice, sales, support, hiring, and finance is visible in the command center and can be exported.
High-risk steps — sending money, mass outbound, irreversible deletes — are built to stop for a human. You configure what “high-risk” means for your company on paid plans that include approvals.
Encryption
Data in transit uses TLS 1.2 or newer. Data at rest uses AES-256 (or equivalent) on the cloud provider. Backups are encrypted. We rotate application secrets and can rotate customer-facing keys on a documented schedule. Enterprise can discuss customer-managed key options in a private region.
Access and identity
Employee access to production is via SSO, MFA, and time-bound roles. We do not use shared root passwords. Access is logged and reviewed. Support staff see customer content only when you open a ticket and grant it, or when required to restore service — and that access is audited.
Your side: use unique work emails, turn on SSO when you have it, and revoke leavers the same day. We will help map IdP groups on Enterprise.
Data and isolation
Workspaces are logically isolated. We do not mix your knowledge base into another customer’s desks. Deletes from the product are removed from primary stores within 30 days and from backups on rotation (typically within 90 days), except where the law requires a hold.
You can export logs and knowledge. On contract close we follow the retention path in the Privacy Policy.
AI and subprocessors
Desks call model APIs for inference. We contract that your content is not used to train the vendor’s public models. We do not train shared Fless models on your files, tickets, or recordings.
Hosting, email, billing, and inference run on named subprocessors. A current list is available under NDA for security review. We will notify workspace owners of material subprocessor changes as required by a DPA.
Operations
Production runs on major cloud providers with network segmentation, patching, and vulnerability scanning. We monitor availability and error budgets. Change management covers production deploys. Logging covers auth, admin, and desk execution.
Developers do not use production customer data in personal environments. Staging uses synthetic or anonymized fixtures.
Incidents
We maintain an incident process: detect, contain, eradicate, recover, and notify. If we confirm a breach of your personal data, we will notify the workspace owner without undue delay and, where the law sets a clock (including GDPR-style 72 hours to authorities), we will meet it.
Status and severe outages are communicated to owners by email or in-product. Ask for the incident contact on Enterprise.
Compliance
We maintain SOC 2 Type II. The report is available to customers under NDA. We will complete reasonable security questionnaires for Enterprise and Scale plans. We support DPAs and, where needed, SCCs for international transfers.
Fless is not a HIPAA BA, PCI merchant-of-record, or ISO 27001 certified environment unless an order form says so. Do not put card PAN or protected health information into desks unless you have a signed addendum that covers it.
Report a vulnerability
If you find a security issue in Fless, email security@fless.com with steps to reproduce. Do not access other customers’ data. We will acknowledge and work the report. We do not run a public bug bounty unless announced here.
Procurement and contact
Security pack, SOC 2, DPA, and subprocessors: security@fless.com
Named rollout and private region: Contact
Legal terms: Terms of Service
