Your ticket data is not our training data.
This is the first thing support leaders ask. Here's the direct answer: Replixa does not use your customer ticket data to train or fine-tune any model. Your data resolves your tickets — it doesn't leave your tenant.
Data handling
Replixa does not use your ticket content, customer messages, or resolution history to fine-tune or retrain any model. Your data processes your tickets — it is never used to improve performance for other customers.
All customer data is stored and processed in AWS US regions. Ticket content, KB data, and API credentials do not leave US infrastructure. GDPR customers can request a Data Processing Agreement for EU-origin data handling.
Ticket resolution history is retained for 90 days by default for audit and debugging purposes. Growth and Scale customers can configure shorter or longer retention windows. Data is purged on account closure within 30 days.
Each account is logically isolated. Replixa's resolution context for Tenant A is never accessible to Tenant B — not in retrieval, not in model context, not in logging. Row-level isolation enforced at the data layer.
Access controls
All helpdesk and business API connections use OAuth 2.0 or scoped API keys — never stored passwords or session tokens. Credentials are encrypted at rest using AES-256 and never exposed in logs.
Replixa requests the minimum scope required for each action type. Stripe read-only for lookups, write scope only when refund actions are enabled. You control which scopes are active from the integrations dashboard.
Every action Replixa takes on a ticket — including resolution text sent, API calls made, and escalation decisions — is logged with timestamps and metadata. Growth and Scale customers have audit log access via the dashboard and API.
Your agents can review, override, or reverse any Replixa action from within your helpdesk. Resolution edits and action revocations are logged. There is no AI action that cannot be reviewed or reversed by your team.
Compliance posture
We're transparent about where we are. We don't claim certifications we don't hold.
We have implemented controls aligned with SOC 2 Type II requirements (security, availability, confidentiality). We have not completed a formal SOC 2 audit — this is on our roadmap. We will not claim SOC 2 compliance until we hold the certification.
For customers subject to GDPR, Replixa can execute a Data Processing Agreement (DPA) that covers how we process EU-resident personal data. Contact [email protected] to request the DPA.
Replixa complies with the Texas Data Privacy and Security Act (TDPSA). As a Texas-based processor, we honor consumer rights requests forwarded by covered businesses and maintain appropriate data handling practices under Texas law.
All data in transit uses TLS 1.2+ minimum. Data at rest is encrypted with AES-256. API credentials, tokens, and KB content are stored encrypted. Encryption keys are managed through AWS KMS with rotation.
Security questions?
Send detailed security inquiries, vulnerability reports, or DPA requests directly to our engineering team. We respond to security questions within one business day.