11x security and compliance overview
11x holds SOC 2 Type II and CASA Tier 3 certification and complies with GDPR and CCPA. Data is encrypted with TLS in transit and AES-256 at rest on AWS.
11x holds SOC 2 Type II and CASA Tier 3 certification, and complies with GDPR and CCPA. Data in transit is protected with TLS; data at rest is encrypted with AES-256 in AWS RDS. Current certifications and documentation are published at the 11x trust center.
Who this applies to: anyone completing a security review or vendor assessment for 11x. Send your security team to the trust center — it's the authoritative, current source. This page summarizes what's there.
Certifications
| Certification | Scope |
|---|---|
| SOC 2 Type II | System Security, Availability, Processing Integrity, Confidentiality, and Privacy. Audited annually; detailed reports available on request. |
| CASA Tier 3 | Identity & Access Management, Data Security, Infrastructure & Virtualisation Security, Application & Interface Security, and Incident Management. |
Regulatory compliance
GDPR
Operations align with GDPR data retention protocols. Data processing agreements are maintained for EU-based customers, with custom DPAs available on Enterprise.
CCPA
The operational framework, including policies and procedures, is maintained in compliance with CCPA requirements.
See also the 11x privacy policy and website tracking privacy policy.
Data security
| Control | Implementation |
|---|---|
| Encryption in transit | TLS for all data in transit |
| Encryption at rest | AES-256 for data stored in AWS RDS |
| Hosting | AWS high-security facilities with continuous on-site security, surveillance, and monitoring |
| Redundancy | Fault-tolerant design; databases run in clustered configurations |
| Scaling | Containerized deployments scaling dynamically |
| Subprocessors | Secure subprocessors facilitate connections to Salesforce and other sales platforms |
Enterprise controls
These are Enterprise-tier capabilities. If your procurement process requires any of them, Enterprise is the only tier that satisfies it — see which plan is right for me.
- SSO
- Custom DPA and SLA
- Custom integrations
What your security review will likely ask
Your responsibilities
Security is shared. These are yours to configure:
Grant least-privilege CRM access
Use a service account with only the object and field permissions your motion needs. See Salesforce or HubSpot.
Protect API credentials
Store them in a secret manager, scope them narrowly, and rotate on a schedule. See webhooks and API.
Configure consent and disclosure
Call recording notices and outbound calling consent are configured by you, per your jurisdiction.
Manage user access
Remove access when people leave, and review who holds admin rights periodically.
Mind transcript sensitivity
Transcripts contain what prospects actually said. Don't pipe full payloads into systems with broad internal access.
Next steps
Trust center
Authoritative, current certifications.
Which plan is right for me?
SSO and custom DPAs are Enterprise-only.
Integrations
Permission scoping and field mapping.
Webhooks and API
Credential handling and webhook security.
Still need help
For security documentation, the SOC 2 report, or a subprocessor list, start at the trust center or email support@11x.ai.