Overview of 11xSecurity and compliance

11x security and compliance overview

11x holds SOC 2 Type II and CASA Tier 3 certification and complies with GDPR and CCPA. Data is encrypted with TLS in transit and AES-256 at rest on AWS.

11x holds SOC 2 Type II and CASA Tier 3 certification, and complies with GDPR and CCPA. Data in transit is protected with TLS; data at rest is encrypted with AES-256 in AWS RDS. Current certifications and documentation are published at the 11x trust center.

Who this applies to: anyone completing a security review or vendor assessment for 11x. Send your security team to the trust center — it's the authoritative, current source. This page summarizes what's there.

Certifications

CertificationScope
SOC 2 Type IISystem Security, Availability, Processing Integrity, Confidentiality, and Privacy. Audited annually; detailed reports available on request.
CASA Tier 3Identity & Access Management, Data Security, Infrastructure & Virtualisation Security, Application & Interface Security, and Incident Management.

Regulatory compliance

See also the 11x privacy policy and website tracking privacy policy.

Data security

ControlImplementation
Encryption in transitTLS for all data in transit
Encryption at restAES-256 for data stored in AWS RDS
HostingAWS high-security facilities with continuous on-site security, surveillance, and monitoring
RedundancyFault-tolerant design; databases run in clustered configurations
ScalingContainerized deployments scaling dynamically
SubprocessorsSecure subprocessors facilitate connections to Salesforce and other sales platforms

Enterprise controls

These are Enterprise-tier capabilities. If your procurement process requires any of them, Enterprise is the only tier that satisfies it — see which plan is right for me.

  • SSO
  • Custom DPA and SLA
  • Custom integrations

What your security review will likely ask

Your responsibilities

Security is shared. These are yours to configure:

Grant least-privilege CRM access

Use a service account with only the object and field permissions your motion needs. See Salesforce or HubSpot.

Protect API credentials

Store them in a secret manager, scope them narrowly, and rotate on a schedule. See webhooks and API.

Configure consent and disclosure

Call recording notices and outbound calling consent are configured by you, per your jurisdiction.

Manage user access

Remove access when people leave, and review who holds admin rights periodically.

Mind transcript sensitivity

Transcripts contain what prospects actually said. Don't pipe full payloads into systems with broad internal access.

Next steps

Still need help

For security documentation, the SOC 2 report, or a subprocessor list, start at the trust center or email support@11x.ai.