Skip to content
pack

Enterprise security review pack

Get a communications platform through security review in one pass. 29 reviewer questions across tenancy, encryption, AI data flows, retention, subprocessors, and continuity, pre-answered for CommsOperator with an honest status on each, so you can see what a complete answer looks like and hold every vendor to it.

The enterprise security review pack pairs the 29 questions a security reviewer should ask any AI communications vendor with CommsOperator's own answers, which say plainly what is shipped, what is partial, what is planned, and what is not offered. It covers tenant isolation, authentication, encryption at rest and in transit, AI data flows and model training, retention and deletion, subprocessors and transfers, logging and audit, incident response, and continuity, then adds a paste-ready data-flow description and the eight commitments to require in writing before signing.

For: Security reviewers, IT, and procurement assessing an AI communications platform, and the champion inside the company who has to get it past them ยท Published 2026-08-26

What is inside

  • 29 reviewer questions in five domains, phrased so a vague answer stands out
  • CommsOperator's answers with a status on each: shipped, partial, planned, or not offered
  • The AI data-flow section most questionnaires still miss: providers, training, prompt scope, logging, kill switch
  • A data-flow description you can paste straight into a review
  • Eight things to require in writing before you sign

Get the Markdown copy

The complete text is on this page already. The form gets you a file to keep and share, downloaded right here. We ask for a work email so we can follow up about this document only.

Use this pack to run a review that covers what the AI does with your mail, not only where the database lives. Most security questionnaires for communications tools were written before an AI agent drafted the message. This one adds the questions that matter now, and answers them for CommsOperator so you can see what a complete answer looks like, including where ours says no, or not yet.

1. Tenancy and access

Ask the vendorCommsOperator's answer
Is isolation logical or physical? Show the mechanism.Logical on the shared instance: every tenant record carries its workspace and reading it requires an explicit membership row. Physical isolation is available as a dedicated instance.
Can any employee of yours read our mail? Under what control?The product has no support-impersonation feature: nobody reads your mail through the application without a workspace membership. Operators of the shared instance hold production database access under the DPA's confidentiality terms, and administrative actions in the product are audit-logged.
What authentication methods are supported?Password (scrypt) or emailed one-time code. No MFA and no SAML or OIDC single sign-on today; both are on the roadmap and not claimed.
How granular is authorization?Four base roles plus custom roles with five permission levels across 15 modules, mailbox-level grants (owner, delegate, read-only), and single-conversation delegation.
How are API credentials issued and revoked?Project-scoped tokens with scopes and expiry, stored as hashes, shown once, revocable per token.

2. Data protection

Ask the vendorCommsOperator's answer
What is encrypted at rest, and with what?Credentials, OAuth tokens, and integration secrets with AES-256-GCM before storage. Database storage is encrypted at rest by the managed database provider. Uploaded files sit on the application server's disk in Falkenstein, and we do not claim disk-level encryption there today.
Who holds the encryption keys? Is there rotation?The application key derives from a deployment secret held in a root-only file on the host. There is no external KMS and no automated rotation yet. A dedicated instance has its own key.
Where does data physically reside?Germany by default: application in Falkenstein, database in Frankfurt (AWS eu-central-1), files on the application server. Dedicated instances in the EU or the US.
What is your backup and restore capability?Continuous backups with point-in-time restore from the managed database provider. Objectives are stated per deployment in the order form; no public figure is advertised.
How is data deleted, and how fast does it leave backups?Workspace deletion cascades; live deletion within 30 days of request; backups cycle out on the provider schedule.

3. AI data flows: the section most questionnaires miss

Ask the vendorCommsOperator's answer
Which model providers see our content, and under which terms?OpenAI's API, GPT-4.1 and GPT-4o family. Under OpenAI's API data usage policy, API content is not used to train OpenAI's models.
Do you train models on customer data?No. We train no models and build no cross-customer profiles.
How much of our mailbox goes into a prompt?The conversation being worked on, retrieved knowledge base content, and relevant CRM fields. Not the mailbox.
Can AI act without a human?Only where an administrator explicitly enables it: automatic delivery for a fixed, reviewed template, or auto-reply on the website chat widget. Everything else drafts for review.
What is logged about each AI action, and for how long?Phase, input, output, decision, tokens, duration, and outcome per step, plus human overrides. A six-month working window is applied; automated purge is not yet enabled.
Can we disable AI entirely?Yes, per workspace, with one toggle.
How do you meet AI transparency law?Auto-sent AI drafts to likely EEA recipients are downgraded to human approval; where a workspace opts out, an AI-origin disclosure is appended.
Can we use our own model or a local one?On a dedicated instance, local inference is available on request.

4. Application and infrastructure security

Ask the vendorCommsOperator's answer
Which security headers and protections are enforced?Content Security Policy, HSTS, nosniff, referrer policy, cross-origin policies. Frame ancestors permit HTTPS origins because the widgets are designed to be embedded; this is a deliberate trade-off, documented.
How is request forgery handled on public endpoints?State-changing requests require a custom header. Anonymous public endpoints are explicitly enumerated and protected by signatures, honeypots, and rate limits instead.
What rate limits exist?Global API, authentication, AI endpoints, public embed endpoints, and per-workspace limits differentiated for free and paid plans.
Are inbound webhooks verified?Yes, with signatures and timing-safe comparison, including billing, mailbox notifications, meeting bots, and the public leads endpoint.
Do you have a penetration test report?Not yet. An annual independent test is on the trust roadmap. We will not claim one we have not had.
Do you have SOC 2 or ISO 27001?No. A SOC 2 Type I engagement is the next step. This pack, the trust center, and the DPA are what we offer today.

5. Operations, incidents, and continuity

Ask the vendorCommsOperator's answer
How do you detect and communicate incidents?Health probes, metrics, error monitoring, and circuit breakers. Severity 1 incidents are notified to the administrative contact with updates at least every two hours and a written summary within five business days.
Is there a public status page?Not yet. Enterprise customers get incident notices by email under the service level framework.
What is your breach notification commitment?Notice without undue delay and within 72 hours of becoming aware, per the DPA.
How are deploys made safe?Immutable releases with a rollback release retained, an in-application notice to signed-in users before a restart, and graceful shutdown that drains schedulers.
What happens to our data if you stop trading?Export during the term and for 30 days after. Mail stays in your own Microsoft 365 tenant throughout, which is the part that matters most.

6. Data flow description you can paste into a review

Mail is authorised through Microsoft Entra by an administrator of the customer's tenant. CommsOperator reads mailbox content through Microsoft Graph over TLS and stores a working copy in a workspace-scoped PostgreSQL database hosted in Frankfurt. OAuth tokens are encrypted with AES-256-GCM before storage and never returned by any API. When a user requests an AI action, the relevant conversation, retrieved knowledge content, and CRM fields are sent to the OpenAI API over TLS; the response is stored as a draft in the same workspace. Sending a message calls Microsoft Graph as the authorised mailbox; the message is delivered by the customer's own Microsoft 365 tenant. Files uploaded by users are stored on the application server's disk in Falkenstein. Billing data goes to Stripe; no card data reaches CommsOperator.

7. What to require in writing before signing

  1. A signed data processing addendum with the Standard Contractual Clauses and, for UK data, the International Data Transfer Addendum.
  2. The subprocessor list, plus subscription to change notices and a right to object.
  3. The deployment region, in the order form, not in an email.
  4. The uptime commitment, support targets, and service credits, with the measurement method.
  5. The breach notification window and the contact it goes to.
  6. Export format and the deletion timeline at termination.
  7. A written statement on model training and on which AI provider sees content.
  8. Whether any claimed certification actually exists today, and the date of the report.
The last one is not cynicism. A vendor that says 'SOC 2 in progress' on a marketing page and cannot produce an engagement letter is telling you something about the rest of its answers.

This is how CommsOperator is run, not just written

If the practice makes sense to you, the product built around it is one request away. Tell us what you run and we will tell you if it fits.