Data Management and Security

SOC II Type 2 certified and GDPR/HIPAA compliant. Every element of SupportLogic SX is designed to keep your data secure.

SupportLogic is certified SOC II Type 2 and compliant with GDPR.

Overview

From end to end, our processes and systems are designed to keep your data secure and maintain a track record of zero breaches or loss of data. Your data passes through three secure elements: a lightweight connector, a data platform, and a web portal. All three are hosted in a virtual private cloud infrastructure.

All data collection happens over SSL using REST APIs. The lightweight data connector connects to your ticketing system using the authentication token that you provide us. 

No credentials are ever shared – you maintain complete control over what and how much data is exposed. Access is maintained in your own VPC instance using self-service OAuth.

Compliance

Security can never be technology alone. All SupportLogic employees and contractors are trained using comprehensive security awareness programs. Every employee is committed to ensuring that the data we analyze within our systems is protected in the highest regard.

Annual SOC 2 Type II certification and GDPR compliance ensure that our policies and procedures meet your security expectations. We regularly conduct both internal and external audits and penetration tests, with complete results available by request.

These data privacy and security protocols also conform to the HIPAA Security, Privacy, and Breach Notification Rules and are designed to meet your HIPAA compliance requirements.

Security Protocols

OAuth/
TLS 1.2+

SHA-256/RSA Encryption

Virtual Private Cloud

FIPS 104-2 Compliance

2-Factor Authentication

Access via Bastion Host

Take a deeper dive: Get the full details behind our secure architecture

Read the White Paper

Data Classification Matrix

Data TypeSensitivityAccessEncryption
Original ticketing dataConfidentialDesignated SupportLogic employees only, using a third-party sync serviceAt rest and in transit
Internal conversationsSensitiveDesignated SupportLogic employees onlyAt rest and in transit
ML predictionsSensitiveDesignated SupportLogic employees onlyAt rest and in transit
ML annotationsSensitiveDesignated SupportLogic employees onlyAt rest and in transit
Product usage dataSensitiveDesignated SupportLogic employees onlyIn transit

Frequently Asked Questions

Is my data secure during extraction?

Yes – All data is encrypted in transit using TLS 1.2 (and above).

Yes – At rest, your data is encrypted under the 256-bit Advanced Encryption Standard, and each encryption key is itself encrypted with a regularly rotated set of master keys.

Yes – Only you can give access to your data by inviting new users to your account or by engaging a third party and explicitly providing access to your data. This access is used to run analytics against your data, with the option to write back to your CRM using SupportLogic SX as a bidirectional solution. Via the ETL, you have the ability to grant or revoke visibility permissions and can remove access permission at any time.

Yes – You can use many industry-standard SSO and Active Directory providers.

The following data types are collected from your CRM system:

  • Case details, notes, comments, and discussions 
  • Case requester details 
  • Agent details 
  • Product usage metrics

Yes – When your account is terminated, SupportLogic will mark all your data for eventual deletion. However, by request your data can be deleted within 3 business days. SupportLogic will delete the case data and send you a confirmation email within one business day.

Your data is only stored in your VPC instance. 

SupportLogic only uses your data for generating the ML models tuned to your organization. Your data is not used to train any other models. Once the models are created the collected data is not needed, SupportLogic may store data to continuously improve your models. SupportLogic can purge any data by request.

SupportLogic does not require login details or a password to your CRM system. However to use the SupportLogic application we require that you to create an account on our platform.

There are two options for account creation: you can create individual user accounts using your email address or sign in with your existing Slack credentials. If you sign in with Slack we collect your profile information.