Encryption in transit
Production traffic is terminated over TLS and internal service access is restricted by cluster networking.
ResponseCX gives security, legal, finance, and CX leaders a clear review path: organization-scoped billing, configurable approvals, action-level audit history, and documented rollout controls.
The strongest trust story is consistency: one onboarding flow, one billing owner, and one visible audit trail from activation through launch.
Architecture, data flow, and billing ownership walkthroughs available on request
Workspace-scoped access and secure payment collection support controlled launches
Sensitive workflow actions can be reviewed by actor, time, and outcome
Humans can review exceptions instead of forcing automation through
These controls matter most when a platform can take real action in your commerce stack.
ResponseCX is built for controlled operational work, not a black-box chatbot deployment.
Teams can review how the product behaves before enabling sensitive workflows in production.
Every workflow should leave a trail that operators and reviewers can understand quickly.
Implemented controls and independent certifications are different things. This register makes that distinction explicit so security teams know what can be verified now and what still requires buyer review.
Production traffic is terminated over TLS and internal service access is restricted by cluster networking.
Kubernetes secrets, primary databases, and production backups use encryption at rest.
Organization scoping, role-aware permissions, approvals, and security-relevant audit events are built into the platform.
The production SLO targets 99.9% availability with health probes, multiple replicas, monitoring, and rollback controls.
ResponseCX maintains SOC 2-aligned technical controls. Certification is not represented here without a current independent report.
Privacy-supporting controls are available; applicability and contractual requirements are confirmed during buyer review.
Payment card collection is hosted by Stripe so card details do not pass through ResponseCX application servers.
Evidence policy v2026-09-01: Only controls marked verified may be described as certified or compliant. Implemented controls must be described as controls, readiness, or supported practices.
This register shows what is contract-verified, what is instrumented in production, and where a reproducible benchmark artifact is still required.
Target: 500 concurrent sessions with <1% server errors
No current evidence artifact — this target is not published as an achieved result.
Target: 99% visible in Chat Desk within 30 seconds
Evidence: config/platform-slos.json#support_email_ingestion
Target: 99.5% successful terminal completion excluding approved escalation
Evidence: config/platform-slos.json#workflow_completion
Target: Published p50 and p95 latency under controlled network conditions
No current evidence artifact — this target is not published as an achieved result.
Target: Fail closed, preserve work, and recover without duplicate customer actions
Evidence: npm run resilience:check
Target: Cross-organization reads and writes rejected across privileged surfaces
Evidence: npm test
Benchmark policy v2026-09-01: Targets are not results. A scenario may be described as proven only when an artifact is attached, the run is reproducible, and the result is within its freshness window.
Walk security and IT stakeholders through data flow, access boundaries, and rollout controls.
Give finance and procurement teams clarity on pricing, invoicing, and ownership before go-live.
Keep sensitive actions visible so teams can inspect what happened and why.
Buyer readiness
Security brief + review path
ResponseCX is easier to buy when trust, billing, and rollout questions are answered in one place.
Use the trust center, pricing page, and onboarding flow together during evaluation.
Commercial controls
Org-scoped billing
Payment methods, invoices, and subscriptions stay tied to the organization rather than individual operators.
That keeps billing changes and recovery paths visible to the right team.
Operational visibility
Approvals + escalation
Sensitive workflows can escalate to a human with context so teams preserve judgment where it matters.
A clean escalation path is part of the trust story, not an exception to it.
Next step
Starter and Growth are designed for controlled self-serve activation. Enterprise can add a guided trust and procurement review without changing the product path.