Legal
Security
Last updated: July 2026
Effective Date: 1 July 2026
Infrastructure Security
Our platform runs on enterprise-grade, security-hardened cloud infrastructure in Australian data centres. All services are deployed in isolated virtual private clouds with strict network segmentation.
Data Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Call media is encrypted end-to-end. Encryption keys are managed via AWS KMS with automatic rotation.
Access Control
We enforce least-privilege access with multi-factor authentication required for all production systems. Access is logged, monitored, and reviewed quarterly. No production data is accessible from development environments.
Compliance Certifications
We are working toward SOC 2 Type II certification and comply with the Australian Privacy Act 1988, GDPR, and HIPAA where applicable.
Vulnerability Management
We run continuous vulnerability scanning, annual penetration testing by independent firms, and maintain a bug bounty program. Critical vulnerabilities are patched within 24 hours.
Incident Response
Our incident response team is available 24/7. In the event of a security incident, affected customers are notified within 72 hours with a detailed post-incident report within 14 days.
Report a Vulnerability
If you discover a security vulnerability, please email security@connectdeep.ai. We acknowledge reports within 24 hours and provide updates throughout the remediation process. We do not pursue legal action against researchers acting in good faith.