Security & Trust Center
How SalesPitch AI protects customer workspaces, governs AI-assisted activity, verifies releases, and distinguishes implemented safeguards from launch work that still requires provider, operational, and professional approval.
The exact policy versions shown here also appear in checkout and onboarding. A future material revision will use a new version and require review where appropriate.
Security and privacy by design
SalesPitch AI is designed to minimize exposed data and authority. Public pages do not receive customer workspace data. Protected application routes authenticate the requesting user, resolve tenant authority on the server, validate inputs, and fail closed when an entitlement, policy, provider, or operational gate is missing.
Security is a continuing operational program, not a one-time feature or guarantee. Controls require monitoring, maintenance, review, and testing as the product and provider environment change.
Data protection and tenant isolation
Customer records are intended to remain scoped to the authorized workspace. Tenant isolation, server-side authorization, encryption in transit, bounded retention, safe exports, reviewed deletion, suppression preservation, and audit evidence form the data-control model. Passwords, API keys, payment-card data, and raw lead files should never be sent through ordinary support email.
Payment-card entry is delegated to Stripe-hosted surfaces when configured. Lead data may enter only from a licensed provider or lawful customer-supplied first-party source. Customer workspace data is not used to train shared models without express authorization.
Identity and access
Protected features are designed around authenticated users, workspace membership, role and entitlement checks, same-origin mutation controls, private no-store responses, secret separation, and revocable provider credentials. Authentication alone does not authorize a provider action; campaign, recipient, consent, timing, suppression, product, and human-approval evidence remain separate gates.
Audit evidence and release verification
Material actions use bounded identifiers, versioned contracts, idempotency, deterministic recovery, and retained status evidence. Every published release is tested locally and then probed on the hosted application and all connected SalesPitch AI domains for exact routes, security headers, content types, indexing boundaries, cookie behavior, protected APIs, and current provider readiness.
See the live Release & Trust Center for the current version and the production-readable readiness boundary.
Availability, recovery, and change control
The production design includes health checks, provider reconciliation, retry-safe requests, idempotent receipts, backup and restore procedures, deployment rollback, rate limits, pause controls, and kill switches. These controls reduce risk but do not promise uninterrupted availability or recovery within a fixed time unless a signed customer agreement states otherwise.
Incident response and security reporting
Suspected abuse, unauthorized access, data exposure, or service integrity issues are classified, contained, investigated, preserved as appropriate evidence, and escalated for notification review. Do not test against customer data or disrupt production.
Security researchers and customers should follow the current instructions in security.txt. Other support and abuse concerns can use the Contact & Support Center.
Responsible AI and human control
C.O.L.T.E.N. AI™ prepares drafts, recommendations, conversation turns, and structured actions within customer instructions and product policy. AI output can be incomplete or wrong and requires appropriate human review. SalesPitch AI does not guarantee a prospect outcome, and an AI recommendation does not replace legal, compliance, financial, employment, or other professional judgment.
Live outreach requires separate recipient, suppression, calling-window, policy, provider, and deployment authority. Review the Acceptable Use & Outreach Policy and Privacy Notice.
Provider readiness, assurance, and certifications
Public readiness is reported from observable production configuration. A connected account or purchased number is not the same as a cleared outbound provider, licensed data source, completed voice evaluation, or approved production campaign. Incomplete gates remain visibly incomplete.
SalesPitch AI does not represent SOC 2, ISO 27001, HIPAA, or PCI DSS certification. Any future compliance or certification claim must be supported by its applicable scope and evidence. Customer launch remains subject to final vendor review, operational testing, and qualified professional review.
Review Data Processing & Vendor Transparency for provider roles, observed status, changes, transfers, and DPA requests.
Read live status, not marketing shorthand.
The public status surface states the deployed release and provider gates without exposing customer, lead, billing, or credential data.
