Your ticket data is not our training data.

This is the first thing support leaders ask. Here's the direct answer: Replixa does not use your customer ticket data to train or fine-tune any model. Your data resolves your tickets — it doesn't leave your tenant.

Data handling

No model training on your data

Replixa does not use your ticket content, customer messages, or resolution history to fine-tune or retrain any model. Your data processes your tickets — it is never used to improve performance for other customers.

Data residency: US (AWS us-east-1)

All customer data is stored and processed in AWS US regions. Ticket content, KB data, and API credentials do not leave US infrastructure. GDPR customers can request a Data Processing Agreement for EU-origin data handling.

90-day retention, configurable

Ticket resolution history is retained for 90 days by default for audit and debugging purposes. Growth and Scale customers can configure shorter or longer retention windows. Data is purged on account closure within 30 days.

No cross-tenant data access

Each account is logically isolated. Replixa's resolution context for Tenant A is never accessible to Tenant B — not in retrieval, not in model context, not in logging. Row-level isolation enforced at the data layer.

Access controls

OAuth-only API authentication

All helpdesk and business API connections use OAuth 2.0 or scoped API keys — never stored passwords or session tokens. Credentials are encrypted at rest using AES-256 and never exposed in logs.

Scoped permissions

Replixa requests the minimum scope required for each action type. Stripe read-only for lookups, write scope only when refund actions are enabled. You control which scopes are active from the integrations dashboard.

Full action audit log

Every action Replixa takes on a ticket — including resolution text sent, API calls made, and escalation decisions — is logged with timestamps and metadata. Growth and Scale customers have audit log access via the dashboard and API.

Human override at any time

Your agents can review, override, or reverse any Replixa action from within your helpdesk. Resolution edits and action revocations are logged. There is no AI action that cannot be reviewed or reversed by your team.

Compliance posture

We're transparent about where we are. We don't claim certifications we don't hold.

SOC 2 controls in design

We have implemented controls aligned with SOC 2 Type II requirements (security, availability, confidentiality). We have not completed a formal SOC 2 audit — this is on our roadmap. We will not claim SOC 2 compliance until we hold the certification.

GDPR — Data Processor Agreement available

For customers subject to GDPR, Replixa can execute a Data Processing Agreement (DPA) that covers how we process EU-resident personal data. Contact [email protected] to request the DPA.

Texas TDPSA

Replixa complies with the Texas Data Privacy and Security Act (TDPSA). As a Texas-based processor, we honor consumer rights requests forwarded by covered businesses and maintain appropriate data handling practices under Texas law.

Encryption in transit and at rest

All data in transit uses TLS 1.2+ minimum. Data at rest is encrypted with AES-256. API credentials, tokens, and KB content are stored encrypted. Encryption keys are managed through AWS KMS with rotation.

Security questions?

Send detailed security inquiries, vulnerability reports, or DPA requests directly to our engineering team. We respond to security questions within one business day.