Trust & Security

Your data. Independently verified.

Backstory meets the standards revenue teams require before signing.
Zero-trust access, end-to-end encryption, and third-party audits every year, not just when we're asked.

5 active certifications  ·  Audited annually

Five controls your security team will ask about.

Backed by independent audits, contractual commitments, and controls you can verify yourself.

Zero-trust access

Every access request gets verified. None get assumed.

  • Zero standing access, provisioning is just-in-time only.
  • Every access event logged: who, what, when.
Why it matters
No one holds standing access to your data. Not even Backstory employees.

Privacy by design

Privacy controls are built into every workflow, not bolted on after.

  • Sensitive and irrelevant data filtered at the point of collection.
  • Every customer record classified confidential by default.
Why it matters
The service only collects what it needs. What's collected never leaves its intended use.

AI-safe by design

Customer data is never used to train AI models.

  • Data used only to deliver contracted services, no exceptions.
  • Production, staging, and development environments fully isolated.
Why it matters
AI governance runs through the same controls as everything else. It isn't a separate program bolted on top.

Operational resilience

If something breaks, recovery is already tested. Not theoretical.

  • Multi-region failover: US-East primary, US-West disaster recovery.
  • Formal incident response playbooks for ransomware, insider threats, and unauthorized access.
Why it matters
Recovery isn't a plan on paper. It's tested on a schedule.

Your data. Your rules.

Control doesn't stop at the contract.

  • Privacy settings you control at the domain, email, and CRM-object level.
  • No persistent employee access to your data or production environments.
Why it matters
These aren't empty promises. They're settings you control.

Security documentation

Everything your security review team needs.

Our security overview covers architecture, certifications, data handling, and our AI governance commitments. Available as a signed PDF.

AI governance

What we commit to on AI and your data.

Revenue data is sensitive. We've documented exactly how AI is used in Backstory, what models see, and what they don't.

Data training
Your data never trains our models.
  • Customer data is never used to train or fine-tune base models.
  • Model outputs are scoped to your tenant, never shared across accounts.
  • Inference requests are logged and available for audit.
Data minimization
Minimal data in. Structured output back.
  • Only the data required for a specific inference is included in any prompt.
  • PII is stripped from activities before data reaches model providers. This includes Backstory's own models, not just third parties.
  • You can opt out of AI features without losing core product functionality.
Compliance coverage
Covered in your DPA. Not a side agreement.
  • AI processing commitments included in the standard Backstory DPA.
  • Covered under SOC 2 Type II scope, independently audited.
  • AI subprocessors listed in our subprocessor registry.
Enterprise controls
Turn off what you don't need.
  • AI features can be disabled at the tenant level without engineering involvement.
  • Role-based controls for which users can view AI-generated content.
  • Audit logs for all AI-generated recommendations accessed by users.

Why technical teams sign off

Independently verified, customer-controlled, and safe by design. The controls security reviewers ask for, already in place.

5 certifications

Renewed annually by independent auditors.

Zero standing access

No persistent employee access to your data.

AI-safe by design

Your data never trains AI models.

Customer-controlled

Granular privacy settings you manage.

Bring your security team.

We'll walk through the controls, answer the questionnaire, and share the SOC 2 report. No pitch, just documentation.