Security, Compliance and BrandBrand protection

Brand protection

What protects your brand when a digital worker speaks for you: knowledge base boundaries, approval modes, escalation rules, disclosure, and reputation assets.

When a digital worker speaks for you, your brand is exposed in two directions: what it says, and how it arrives. The first is governed by knowledge base boundaries, approval mode, and escalation rules. The second by sending domain and caller ID reputation. Both are configurable, and neither is safe by default.

The single highest-leverage control is the boundaries section of your knowledge base - the claims a digital worker must never make. Absence of a claim is not a prohibition on making it. Write the prohibitions down as explicitly as you write the positioning.

What it says

Boundaries in the knowledge base

Record explicitly:

BoundaryExample
Unsupported performance claimsNumbers you cannot substantiate
Compliance and security assertionsCertifications, data residency specifics
Roadmap or delivery commitmentsAnything not shipped
Pricing beyond your published postureDiscounts, terms
Competitor characterisationsClaims about another vendor's product
Legal or contractual languageAnything a contract governs

See knowledge base.

Approval mode

Three levels, in increasing autonomy. Choose per segment and per motion, not once for the whole workspace.

Escalate through these in order. Teams that start on autopilot and later discover a boundary problem have usually already sent the message that causes it.

Escalation

Make these unconditional handoffs to a human regardless of confidence:

  • Pricing beyond your published posture
  • Contract, legal, or procurement terms
  • Security and compliance specifics
  • Roadmap or delivery commitments
  • Anything from a named strategic account or an existing customer
  • Any explicit request to speak to a person

See smart replies and call flows.

Tone

Feed real call transcripts into the knowledge base. Transcripts teach the language your buyers actually use far better than a tone instruction does. Messaging also adapts by channel and by persona - see AI personalization.

Disclosure

Whether and how a digital worker identifies itself, and any call recording notice, is configured by you per your policy and jurisdiction. See consent and calling compliance.

How it arrives

Your sending domain and phone numbers are brand assets. Damage to either is slow to repair.

AssetProtection
Corporate email domainSend outbound from a dedicated subdomain or separate domain, so outbound reputation never touches transactional and internal mail
Sending reputationAutomatic authentication, warm-up, placement testing before volume, and rotation of degraded domains
Message constructionPlain text by default, no tracking pixels, and every message unique - identical bulk mail is itself a spam signal
Caller IDBranded caller ID with rotating numbers, plus automatic pause and remediation when a number is flagged
Logo in the inboxBIMI displays your verified logo once DMARC is at enforcement - check with the BIMI checker

Domain isolation is the decision people regret skipping. If outbound reputation is damaged on your primary corporate domain, it affects invoices, password resets, and internal mail - not just campaigns. Decide this before you send, because moving later means warming a new domain from scratch.

Your data is not training a model

Per the 11x terms, you retain ownership of the data you submit. 11x receives a non-exclusive, royalty-free licence to fulfil the service, uses data only in aggregate and anonymised form, and does not train AI models on confidential information.

Frequently Asked Questions

Next steps

Need help?

Email support@11x.ai, or book time with the team.