Security
Security-first practices.
This page exists to answer the question honestly, not to make our sales pitch sound more official. We do not hold SOC 2, ISO 27001, or HIPAA certification. What follows are the concrete practices we do follow, across both Enso PM and Enso FM.
Encryption in transit
Every Enso property runs on HTTPS, with HTTP requests redirected and modern transport security headers set on every response.
Least-privilege access
Authentication uses hashed, salted passwords and rate-limited sign-in. Internal roles are scoped to what a job needs — a support login is not a database login.
Tenant isolation
Customer data is scoped by organization at the data layer, not just in the interface, so one customer's records are never reachable through another's session.
Privileged access is logged
When Enso staff need to look at a customer's account to help them, that access is read-only by default and recorded — who, when, what changed.
Rate limiting
Public endpoints — sign-in, inbound webhooks, phone and messaging callbacks — are rate limited so a single bad actor can't exhaust them.
Retention & redaction
Data has a defined retention window. Where the record itself is useful but the personal detail inside it isn't needed long-term, we redact rather than keep it indefinitely.
Subprocessor discipline
We use a limited set of vetted vendors to host, run, and carry the service — never sold, never used for advertising. Every one of them is named on this page.
Audit logging in the products
Enso PM and Enso FM record who did what inside the product, so account activity is reviewable, not just visible in the moment.
Subprocessors
These are every third party that can touch data on our behalf. We publish the list rather than hold it behind a request, because you should not have to email a vendor to find out who else is in the chain. None of them receive data for advertising, and none of them are permitted to use it for their own purposes.
Running the service
Involved in delivering Enso PM and Enso FM to customers and their contacts.
| Subprocessor | What it does | Processing region |
|---|---|---|
| Anthropic | AI models behind the voice, email, and text agents | United States |
| Twilio | Inbound and outbound voice and SMS carriage | United States |
| ElevenLabs | Synthesised speech for the phone agents | United States |
| Postmark | Transactional email delivery and inbound email routing | United States |
| Stripe | Payments and subscription billing | United States |
| Vercel | Application hosting for app.ensofm.ai | United States |
| Neon | Managed Postgres for the application database | United States |
| Render | Backend service hosting and its database | United States |
| Sentry | Application error monitoring | United States |
Website and sales enquiries
These see enquiry details submitted through our websites. They do not see customer product data.
| Subprocessor | What it does | Processing region |
|---|---|---|
| Hostinger | Hosting for the marketing sites (this one, ensopm.ai, ensofm.ai) | European Union |
| HubSpot | CRM for sales enquiries submitted through our forms | United States |
| Make.com | Routes website enquiries into the CRM | European Union |
We will tell you before a new subprocessor starts handling customer data. Ask support@ensointegration.ai to be added to that notice list.
Retention and deletion
Conversation transcripts, recordings, and the records built from them are retained for as long as your account is active, on the retention window configured for your organization. Where the record stays useful but the personal detail inside it does not, we redact rather than keep it indefinitely.
You can ask for your data at any time, in a machine-readable export, and you can ask us to delete it. On deletion we remove customer data from production systems within 30 days; encrypted backups age out on their own rolling schedule after that, and we do not restore deleted data from them. Where a law requires us to keep something — billing records, for example — we keep only that, and only for as long as required.
If you close your account and ask for nothing, we delete customer data 90 days after the account closes.
Data processing agreement
For the data your customers, residents, and callers hand us, you are the controller and Enso is the processor. We sign a DPA on that basis, including the standard processor commitments — process only on your instructions, keep our staff under confidentiality, help you answer data-subject requests, and tell you about a breach. A DPA is available on request from support@ensointegration.ai and we will send it before you sign anything, not after.
Incident response
We are a small team, so we will be straight about what that means. There is no 24/7 security operations centre. What there is: error monitoring and alerting on the production services, a named person responsible for triaging anything that fires, and a standing commitment that if customer data is exposed we will tell affected customers what happened, what was involved, and what we did about it — within 72 hours of confirming it, and without waiting until we have a tidy story.
Questions, answered
- Do you sell or share our data?
- No. Data is used to run the service. The vendors involved are limited to what's needed to host, run, and carry the service — never advertising, never resale.
- How long is data kept?
- Retention follows defined windows per data type rather than being kept indefinitely by default. Ask us for specifics on the data you're asking about.
- Who inside Enso can access our data?
- Access follows least-privilege — internal roles are scoped to what a job needs. When staff need to look at a customer's account to help them, that access is read-only by default and logged.
- Can you provide a subprocessor list or sign a DPA?
- Yes. Email us for the current subprocessor list; data processing agreements are handled case by case.
- Are you SOC 2 or ISO 27001 certified?
- No — see "On certifications" below. We'd rather publish concrete practices than imply a badge we don't hold.
- What happens if there's a security incident?
- We investigate promptly and notify affected customers as required. This page will stay honest about where that process stands as it matures.
On certifications
We would rather tell you plainly where we stand than imply something we can't back up. Enso AI does not currently hold SOC 2, ISO 27001, or HIPAA certification, and doesn't describe itself as "compliant" with any of them. The practices above are real and in place today; formal certification is a separate process we haven't completed.
Vulnerability disclosure
If you have found a security issue, email support@ensointegration.ai with enough detail to reproduce it. The same address is published at /.well-known/security.txt on each of our sites.
We will acknowledge your report within three business days and tell you what we intend to do about it. We do not run a paid bounty programme, and we will not threaten you with legal action for research done in good faith: stay within your own test account, do not access other people's data, do not degrade the service for anyone else, and give us a reasonable window to fix it before publishing.
Anything else
For a question this page does not answer, email support@ensointegration.ai and we'll route it to the right team.