5 active certifications · Audited annually
Zero-trust access
Every access request gets verified. None get assumed.
- Zero standing access, provisioning is just-in-time only.
- Every access event logged: who, what, when.
Privacy by design
Privacy controls are built into every workflow, not bolted on after.
- Sensitive and irrelevant data filtered at the point of collection.
- Every customer record classified confidential by default.
AI-safe by design
Customer data is never used to train AI models.
- Data used only to deliver contracted services, no exceptions.
- Production, staging, and development environments fully isolated.
Operational resilience
If something breaks, recovery is already tested. Not theoretical.
- Multi-region failover: US-East primary, US-West disaster recovery.
- Formal incident response playbooks for ransomware, insider threats, and unauthorized access.
Your data. Your rules.
Control doesn't stop at the contract.
- Privacy settings you control at the domain, email, and CRM-object level.
- No persistent employee access to your data or production environments.
Security documentation
Everything your security review team needs.
Our security overview covers architecture, certifications, data handling, and our AI governance commitments. Available as a signed PDF.
AI governance
What we commit to on AI and your data.
Revenue data is sensitive. We've documented exactly how AI is used in Backstory, what models see, and what they don't.
- Customer data is never used to train or fine-tune base models.
- Model outputs are scoped to your tenant, never shared across accounts.
- Inference requests are logged and available for audit.
- Only the data required for a specific inference is included in any prompt.
- PII is stripped from activities before data reaches model providers. This includes Backstory's own models, not just third parties.
- You can opt out of AI features without losing core product functionality.
- AI processing commitments included in the standard Backstory DPA.
- Covered under SOC 2 Type II scope, independently audited.
- AI subprocessors listed in our subprocessor registry.
- AI features can be disabled at the tenant level without engineering involvement.
- Role-based controls for which users can view AI-generated content.
- Audit logs for all AI-generated recommendations accessed by users.
Why technical teams sign off
Independently verified, customer-controlled, and safe by design. The controls security reviewers ask for, already in place.
Renewed annually by independent auditors.
No persistent employee access to your data.
Your data never trains AI models.
Granular privacy settings you manage.
Bring your security team.
We'll walk through the controls, answer the questionnaire, and share the SOC 2 report. No pitch, just documentation.
