Data protection
Website and service data travels over HTTPS connections. During solution design, we define data sources, purpose, and required retention, and avoid collecting fields the process does not need.
- Data minimization for the task
- Project and environment separation according to the agreed design
- Retention and deletion rules defined with the client
- No sale of client data or use for advertising
Access control
Each integration receives the least access needed for its task. An agent should not have broad system access when the process only requires reading or updating specific records.
- Least-privilege access
- Service accounts separated from employee accounts where possible
- Permission review when scope changes
- Access disabled when no longer required
Monitoring and response
Events that require logging and alerts are defined before launch. For managed services, errors and integrations are monitored within the agreed support scope, and incidents are escalated according to impact.
- Logs for important messages and actions
- Alerts for integration failures or rule breaches
- Ability to pause automated actions
- Incident and corrective-action documentation
Vendors and data processors
Solutions may rely on hosting, AI model, email, and integration providers approved for the project. We explain vendor categories and data flow in the solution design; each provider’s terms and controls remain part of the assessment.
- Frontend and service hosting
- AI model providers
- Email and notification services
- Client systems such as CRM, calendar, and accounting
Report a security issue
If you discover a vulnerability or unexpected behavior, send a description and reproduction steps to hello@falaqai.com. Avoid sensitive data in the first message; we will arrange an appropriate channel if needed.