Version: 1.1
Classification: Public
Last Updated: July 2, 2026
Slick AI is committed to maintaining the highest standards of security and data protection for our enterprise customers. This document provides an overview of our security architecture, controls, and compliance measures.
┌─────────────────────────────────────────────────┐
│ USERS │
├─────────────────────────────────────────────────┤
│ CloudFlare (DDoS/WAF) │
├─────────────────────────────────────────────────┤
│ Application Load Balancer │
├─────────────────────────────────────────────────┤
│ ┌──────────┐ ┌──────────┐ │
│ │ API │ │ Web │ │
│ │ Gateway │ │ Server │ │
│ └──────────┘ └──────────┘ │
├─────────────────────────────────────────────────┤
│ ┌──────────────────────────┐ │
│ │ Application Services │ │
│ │ (Slickflow Engine, AI) │ │
│ └──────────────────────────┘ │
├─────────────────────────────────────────────────┤
│ ┌────────┐ ┌────────┐ ┌────────┐ │
│ │Database│ │Storage │ │ Cache │ │
│ │ (RDS) │ │ (S3) │ │ (Redis)│ │
│ └────────┘ └────────┘ └────────┘ │
└─────────────────────────────────────────────────┘
All within AWS VPC| Region | Location | Compliance | Primary Use |
|---|---|---|---|
| EU-WEST-1 | Ireland | GDPR | Active region — all customers |
EU-West (Ireland) is the only active region today. US-EAST-1 (Virginia) and ME-SOUTH-1 (UAE) are not currently active; additional regions may be enabled for eligible customers in the future.
We implement multiple layers of security:
Tenant A Tenant B
│ │
├─ Isolated Database ├─ Isolated Database
├─ Separate S3 Prefix ├─ Separate S3 Prefix
└─ Unique API Keys └─ Unique API Keys
AES-256 at rest via AWS KMS (BYOK available on request)| Data Type | Default Retention | Deletion Method |
|---|---|---|
| Conversations | Up to 24 months, then automatically deleted; enterprise per contract | Cryptographic deletion |
| Voice recordings | 7 days | Permanent deletion |
| Customer profiles | 12 months | GDPR-compliant purge |
| Audit logs | 90 days | Automated cleanup |
| Operational / diagnostic logs | 30 days (no conversation content) | Automated cleanup |
| Backups | 30 days | Encrypted deletion |
Conversation data is retained for up to 24 months from the date each message is created, then automatically deleted. Operational and diagnostic logs, which do not contain conversation content, are kept for 30 days. Enterprise and regulated customers may be subject to a different retention period per their agreement, which may be extended to meet record-keeping obligations (for example, financial-services clients subject to regulatory record retention). Users can request erasure of their data at any time.
Roles (tenant-scoped):
tenant_admin:
- Full tenant administration
- User & role management
- Configuration & billing
tenant_user:
- Day-to-day operations
- Handle conversations
- Limited configuration
viewer:
- Read-only access
- Report viewing| Provider | Data Retention | Security Measures |
|---|---|---|
| Amazon Bedrock (AWS) | Transient (not retained; not used for training) | Primary Claude inference path; in-AWS inference, enterprise agreement |
| Anthropic | Zero retention | Direct Enterprise API (also served via Bedrock), no training on customer data |
| Microsoft Azure (AI Foundry) | Transient (not retained; not used for training) | Fallback hosting for specific model tiers, enterprise agreement |
| OpenAI | Zero retention (API mode) | Enterprise agreement, DPA signed |
| Google Vertex AI | 55 days (abuse only) | Regional endpoints, data processing agreement |
Provider applicability is scoped by product and plan. Claude-based tenants use Anthropic via Amazon Bedrock (with Anthropic's direct API and Azure AI Foundry as fallback); OpenAI and Google Vertex AI apply to other products/models.
Response Team Structure:
Incident Commander
├─ Security Lead
├─ Engineering Lead
├─ Communications Lead
└─ Customer Success LeadResponse SLAs:
| Severity | Detection Target | Response Time | Resolution Target |
|---|---|---|---|
| Critical | < 15 minutes | < 1 hour | < 4 hours |
| High | < 1 hour | < 2 hours | < 24 hours |
| Medium | < 4 hours | < 8 hours | < 72 hours |
| Low | < 24 hours | < 48 hours | < 7 days |
| Standard | Status | Details |
|---|---|---|
| GDPR | Aligned | Core requirements implemented; customer-controller support via DPA/SCCs |
| CCPA/CPRA | Aligned | Consumer rights supported; opt-out mechanisms |
| KVKK | Aligned | Turkish data protection safeguards; transfer assessments |
| DIFC DPL | Aligned | Local processing & transfer safeguards |
2026 Q3: ━━━━━━━━━━━━━━━━━━━━┓
Security Baseline ┃
┃
2026 Q4: ━━━━━━━━━━━━━━━━━━━━╋━━━━━┓
SOC 2 Type II Audit ┃ ┃
(in progress) ┃ ┃
2027 Q1: ━━━━━━━━━━━━━━━━━━━━┛ ┃
SOC 2 Report Targeted ┃
┃
2027 Q2: ━━━━━━━━━━━━━━━━━━━━━━━━━━┛
ISO 27001 Certification (targeted)Security Team
Email: [email protected]
Response Time: Within 48 hours
For critical issues: Mark email as "URGENT - SECURITY"
PGP: www.getslick.ai/pgp
Data Protection Officer
Email: [email protected]
Response Time: Within 48 hours
See our Security Hall of Fame for credited researchers.
Our security team is available to discuss your specific requirements.
Contact Security Team© 2026 Slick AI. All rights reserved.
This document is proprietary and confidential. It may be shared with customers and prospects under NDA.
Document Classification: Public
Version: 1.1
Last Review: July 2, 2026
Next Review: October 2, 2026