Skip to content
Enso AI

Security

Security-first practices.

This page exists to answer the question honestly, not to make our sales pitch sound more official. We do not hold SOC 2, ISO 27001, or HIPAA certification. What follows are the concrete practices we do follow, across both Enso PM and Enso FM.

Encryption in transit

Every Enso property runs on HTTPS, with HTTP requests redirected and modern transport security headers set on every response.

Least-privilege access

Authentication uses hashed, salted passwords and rate-limited sign-in. Internal roles are scoped to what a job needs — a support login is not a database login.

Tenant isolation

Customer data is scoped by organization at the data layer, not just in the interface, so one customer's records are never reachable through another's session.

Privileged access is logged

When Enso staff need to look at a customer's account to help them, that access is read-only by default and recorded — who, when, what changed.

Rate limiting

Public endpoints — sign-in, inbound webhooks, phone and messaging callbacks — are rate limited so a single bad actor can't exhaust them.

Retention & redaction

Data has a defined retention window. Where the record itself is useful but the personal detail inside it isn't needed long-term, we redact rather than keep it indefinitely.

Subprocessor discipline

We use a limited set of vetted vendors to host, run, and carry the service — never sold, never used for advertising. Every one of them is named on this page.

Audit logging in the products

Enso PM and Enso FM record who did what inside the product, so account activity is reviewable, not just visible in the moment.

Subprocessors

These are every third party that can touch data on our behalf. We publish the list rather than hold it behind a request, because you should not have to email a vendor to find out who else is in the chain. None of them receive data for advertising, and none of them are permitted to use it for their own purposes.

Running the service

Involved in delivering Enso PM and Enso FM to customers and their contacts.

SubprocessorWhat it doesProcessing region
AnthropicAI models behind the voice, email, and text agentsUnited States
TwilioInbound and outbound voice and SMS carriageUnited States
ElevenLabsSynthesised speech for the phone agentsUnited States
PostmarkTransactional email delivery and inbound email routingUnited States
StripePayments and subscription billingUnited States
VercelApplication hosting for app.ensofm.aiUnited States
NeonManaged Postgres for the application databaseUnited States
RenderBackend service hosting and its databaseUnited States
SentryApplication error monitoringUnited States

Website and sales enquiries

These see enquiry details submitted through our websites. They do not see customer product data.

SubprocessorWhat it doesProcessing region
HostingerHosting for the marketing sites (this one, ensopm.ai, ensofm.ai)European Union
HubSpotCRM for sales enquiries submitted through our formsUnited States
Make.comRoutes website enquiries into the CRMEuropean Union

We will tell you before a new subprocessor starts handling customer data. Ask support@ensointegration.ai to be added to that notice list.

Retention and deletion

Conversation transcripts, recordings, and the records built from them are retained for as long as your account is active, on the retention window configured for your organization. Where the record stays useful but the personal detail inside it does not, we redact rather than keep it indefinitely.

You can ask for your data at any time, in a machine-readable export, and you can ask us to delete it. On deletion we remove customer data from production systems within 30 days; encrypted backups age out on their own rolling schedule after that, and we do not restore deleted data from them. Where a law requires us to keep something — billing records, for example — we keep only that, and only for as long as required.

If you close your account and ask for nothing, we delete customer data 90 days after the account closes.

Data processing agreement

For the data your customers, residents, and callers hand us, you are the controller and Enso is the processor. We sign a DPA on that basis, including the standard processor commitments — process only on your instructions, keep our staff under confidentiality, help you answer data-subject requests, and tell you about a breach. A DPA is available on request from support@ensointegration.ai and we will send it before you sign anything, not after.

Incident response

We are a small team, so we will be straight about what that means. There is no 24/7 security operations centre. What there is: error monitoring and alerting on the production services, a named person responsible for triaging anything that fires, and a standing commitment that if customer data is exposed we will tell affected customers what happened, what was involved, and what we did about it — within 72 hours of confirming it, and without waiting until we have a tidy story.

Questions, answered

Do you sell or share our data?
No. Data is used to run the service. The vendors involved are limited to what's needed to host, run, and carry the service — never advertising, never resale.
How long is data kept?
Retention follows defined windows per data type rather than being kept indefinitely by default. Ask us for specifics on the data you're asking about.
Who inside Enso can access our data?
Access follows least-privilege — internal roles are scoped to what a job needs. When staff need to look at a customer's account to help them, that access is read-only by default and logged.
Can you provide a subprocessor list or sign a DPA?
Yes. Email us for the current subprocessor list; data processing agreements are handled case by case.
Are you SOC 2 or ISO 27001 certified?
No — see "On certifications" below. We'd rather publish concrete practices than imply a badge we don't hold.
What happens if there's a security incident?
We investigate promptly and notify affected customers as required. This page will stay honest about where that process stands as it matures.

On certifications

We would rather tell you plainly where we stand than imply something we can't back up. Enso AI does not currently hold SOC 2, ISO 27001, or HIPAA certification, and doesn't describe itself as "compliant" with any of them. The practices above are real and in place today; formal certification is a separate process we haven't completed.

Vulnerability disclosure

If you have found a security issue, email support@ensointegration.ai with enough detail to reproduce it. The same address is published at /.well-known/security.txt on each of our sites.

We will acknowledge your report within three business days and tell you what we intend to do about it. We do not run a paid bounty programme, and we will not threaten you with legal action for research done in good faith: stay within your own test account, do not access other people's data, do not degrade the service for anyone else, and give us a reasonable window to fix it before publishing.

Anything else

For a question this page does not answer, email support@ensointegration.ai and we'll route it to the right team.