Security

Security

NeuralDesk is designed to keep customer conversations, training content, and workspace controls protected from ingestion through response delivery.

Security overview updated July 18, 2026

Need a review? Security, privacy, and procurement teams can contact security@neuraldesk.io for questionnaires, DPA requests, and architecture details.

Security program

NeuralDesk applies defense-in-depth controls across application, infrastructure, data, and operational workflows. We focus on practical safeguards that reduce real risk for teams deploying AI in customer-facing support.

Access control

Role-based permissions, protected admin surfaces, session controls, and least-privilege internal access keep workspaces isolated.

Encryption

Data is encrypted in transit with TLS and at rest using managed storage and database encryption capabilities.

Data boundaries

Customer training sources, chunks, conversations, and integrations are scoped to the owning workspace.

Monitoring

Operational logs, queue health, usage signals, webhook records, and suspicious activity patterns are monitored for anomalies.

Vendor review

Subprocessors are selected for reliability, security posture, and contractual safeguards around customer data.

Incident response

Security events are triaged by severity with customer notification when data, availability, or account integrity is affected.

AI data handling

Your training content and conversations are used to operate your assistants. They are not sold, shared between customers, or used to train shared foundation models. Workspace admins can manage sources, delete content, and review generated conversations.

Responsible disclosure

If you believe you found a vulnerability, email security@neuraldesk.io with reproduction steps, impact, and affected URLs or account context. Please avoid accessing data that is not yours and give our team reasonable time to investigate before public disclosure.

Compliance support

Customers can request security documentation, subprocessor information, and a Data Processing Addendum from our team. See the Privacy Policy and Data Processing Agreement for more detail.