Last updated: July 22, 2026
AI Sales Assistant is built for Canadian small and medium businesses. We know you are trusting us with customer conversations, contact details, and appointment data. This page explains how we protect that information in plain language. For legal detail, see our Privacy Policy and Terms of Service.
Enterprise-grade security with TLS encryption and modern browser security standards. We use industry-standard cloud providers, encrypt data in transit, and isolate each customer's data in our application.
Independent scans in July 2026: SecurityHeaders.com grade A, Mozilla Observatory grade B+ (80/100). Both tools also show warnings about our Content-Security-Policy — expected tradeoffs for our stack, not silent oversights. Details below.
unsafe-inline and unsafe-eval in script-src. Next.js and Clerk require these today for sign-in, billing, and dashboard hydration. The rest of the policy still restricts scripts to approved domains (Clerk, Stripe, and our own origins). Removing these directives would need a larger nonce-based CSP rollout — on our security roadmap, not something we can flip overnight. Mozilla Observatory applies a −20 point penalty for the same reason (9 of 10 tests pass; overall grade B+).Access-Control-Allow-Origin: * is intentional on our public widget APIs (/api/chat and /api/widget-config) so the chat widget can run on your website. Protected dashboard APIs do not use a wildcard — they require an authenticated Clerk session. The scanner may also flag this header on public marketing pages; that does not expose customer data.www.aisalesassistant.ca. This is a known limitation when testing Vercel-hosted sites from SSL Labs, not a customer-facing outage.Organization members have role-based access. Owners manage billing and invitations. Managers can run day-to-day operations such as leads, appointments, team profiles, SMS, and follow-up, but cannot access billing or invite new members.
Website visitors chat with an AI assistant configured by your business. Here is what happens to that data:
See OpenAI API data usage policies and our Privacy Policy for more detail.
Cancelling your subscription: cancel through the Stripe customer portal (Settings → Billing). Paid features, including the website widget, stay active until the end of your current billing period. After that, the widget stops serving visitors; dashboard access and stored lead data remain unless you ask us to delete your account. See our Privacy Policy for retention details and plan downgrade behavior.
AI Sales Assistant runs on trusted cloud infrastructure. Subprocessors include:
Each provider processes data according to its own privacy policy and our agreements with them. See our Privacy Policy for the full list.
AI Sales Assistant is operated from Canada. If you access the Service from other regions, your information may be processed in Canada and in locations where our subprocessors operate (including the United States). See Privacy Policy — International users for details.
Database hosting through Neon includes provider-managed backups and point-in-time recovery capabilities. We rely on these infrastructure protections to help recover from accidental data loss or outages.
Live service availability for the web application, database, and chat widget is published on our system status page. External uptime monitors also watch our health check endpoint for automated alerts. We do not publish historical uptime percentages until enough monitoring data exists — check the status page for current component health.
We are honest about what we have today versus what we are working toward. We do not display certifications we have not earned.
| Standard / activity | Status |
|---|---|
| PIPEDA-aligned privacy practices | Active today |
| Public Trust Center and security headers | Active today |
| Public system status page | Active today |
| Independent penetration test | Planned when customer demand warrants |
| SOC 2 Type II | Planned for future enterprise customers |
| ISO 27001 | Not currently planned |
If you believe you have found a security vulnerability in AI Sales Assistant, please report it responsibly. We welcome good-faith security research and will not pursue legal action against researchers who follow these guidelines:
Security contact: ankur.tamhane@artillac.com
We aim to acknowledge reports within 72 hours.
General privacy questions: ankur.tamhane@artillac.com
Legal documents: Privacy Policy · Terms of Service