At Gladly, safeguarding customer data is not just a priority—it’s the foundation of everything we do. We’ve built a robust security infrastructure with stringent measures and advanced encryption protocols. These protections extend across our entire platform, from AI-driven features to payment processing, ensuring industry-leading compliance standards. Our commitment to data security, privacy, and integrity ensures your information remains protected at every touchpoint. Below, you’ll find an in-depth look at the steps we take to uphold these standards.
Visit https://trust.gladly.com/ to find documentation of our compliance with global standards, including certifications, attestations, and audit reports.
AI and Data Security #
Gladly’s AI enhances the customer experience while ensuring comprehensive data protection. Our AI is integrated through enterprise-grade APIs, generating contextually accurate responses to customer inquiries.
No Public Model Usage
Gladly does not require new customer data to train our proprietary models, nor do we provide customer data to any third parties to train their models, including large language models.
Data Privacy and Protection
Customer messages processed by our AI are never used to train AI models. AI vendors store data temporarily (up to 30 days) solely for monitoring purposes, such as detecting abuse or misuse, and then delete it unless required otherwise by law.
Encryption Standards
Gladly uses industry-standard encryption to protect all data in transit and at rest. This includes AES-256 encryption and TLS 1.2 for data transfer, ensuring that sensitive customer information remains secure.
Third-Party Audits and Compliance
Gladly’s AI partners, Azure, OpenAI, and Deepgram, are SOC 2 Type 2 and PCI Compliance and undergo annual penetration testing by third-party security auditors. These tests identify and fix potential vulnerabilities before they can be exploited. Additionally, Gladly maintains a Data Processing Agreement (DPA), which outlines how customer data is handled securely and in compliance with data protection regulations, such as GDPR.
System safeguards and control mechanisms #
Gladly employs several control mechanisms and system safeguards to prevent misuse of AI features and ensure customer interactions remain secure and accurate.
Entity Identification
When training our internal model, Gladly automatically identifies and removes any personally identifiable information (PII) (e.g., names, addresses, emails) to ensure that sensitive customer data is not exposed during the AI’s learning process.
Guardrails for AI Responses
Built-in safeguards are in place to ensure Gladly AI-powered features remain reliable and accurate. This includes:
- Content detection: Identifying sensitive or inappropriate content and rerouting it to a human agent.
- Hallucination prevention: Ensuring AI-generated responses are based on factual, approved content from your knowledge base.
- ~~Action limitations: Restricting the AI from performing tasks outside of its predefined capabilities, ensuring secure and on-brand interactions.~~
- Action limitations and knowledge reliance: AI generates responses based on information provided in Gladly Answers. It is restricted from performing tasks outside of its predefined capabilities, ensuring a secure and on-brand tone in interactions.
- Quality assurance: A review is conducted to ensure all responses adhere to approved content and align with brand standards.
Data Retention and Usage
For any customer conversation handled by AI, messages are processed temporarily to respond but are never retained or used for model training. Data retention is limited to 30 days for abuse detection purposes, after which it is deleted.
Compliance and Certification #
Gladly adheres to a range of global security standards and regulations to ensure customer data is processed and stored securely.
SOC 2 Type 2 and PCI Compliance
Gladly’s AI partners, Azure and Deepgram, are SOC 2 Type and PCI compliant, ensuring our systems meet rigorous security, availability, processing integrity, and confidentiality standards. Additionally, Gladly is PCI-DSS compliant, ensuring that payment data is processed securely and complies with industry regulations. Gladly runs redaction logic before sending the data to any third-party vendor.
DPA with Partners
We have signed Data Processing Agreements (DPAs) with all third-party vendors to ensure data is handled per GDPR and other data protection laws. These agreements outline how data is stored, processed, accessed, and used to ensure compliance with legal and security standards.
Voice Transcription Security #
Gladly uses Deepgram for Voice Summaries to transcribe and summarize voice interactions, ensuring the protection of sensitive customer data.
Data Security
Deepgram is SOC 2 Type and PCI compliant, meaning it adheres to the highest standards of data protection and confidentiality. All voice transcriptions and summaries are processed securely, and Gladly retains data ownership. Deepgram is the data custodian, ensuring that all sensitive information is stored and processed securely.
Data Handling
Our DPA with Deepgram ensures that voice data is always protected, following strict security protocols, including GDPR compliance, data breach reporting, and cooperation with relevant authorities. Voice data is used solely for transcription and summarization, with no unauthorized access or processing.
Privacy and Compliance with Data Protection Regulations #
Gladly is fully committed to ensuring the platform complies with privacy regulations such as CCPA and GDPR. We provide tools and processes to ensure customers are fully informed about how their data is collected and processed.
Customer Consent
Businesses can use Gladly to obtain explicit consent from customers for the collection and use of their personal data in accordance with GDPR and other privacy regulations. This can include pre-chat disclaimers and automated consent messages.
Data Subject Requests
Customers have the right to request the deletion of their data or conversation history and Gladly provides functionality to manage Data Subject Requests efficiently and securely.
Conclusion #
Gladly’s commitment to security spans across all aspects of the platform, from AI processing to payment handling. With industry-standard encryption, compliance with global regulations like SOC 2 Type 2 and PCI-DSS, and advanced data protection protocols, we ensure your customer data is always protected. As we continue to evolve our platform and integrate more advanced AI technologies, we remain dedicated to maintaining the highest standards of security, privacy, and compliance.