
ChatBeacon cloud and dedicated private cloud services are hosted on Microsoft Azure. Microsoft maintains certifications, attestations, and authorizations for applicable Azure services, including SOC 2, ISO/IEC 27001, PCI DSS, and FedRAMP. These assurances apply to Microsoft Azure infrastructure and do not represent a separate certification of ChatBeacon.
Depending on deployment and configuration, ChatBeacon supports encryption in transit, enterprise identity integration, role-based access, audit logging, configurable retention, and customer-controlled AI connectivity. Organizations can deploy ChatBeacon in the cloud, in a dedicated private cloud, or on-premise according to their security, data-control, and operational requirements.
Cloud and dedicated private cloud deployments with customer-selected Azure regions to support data residency and operational requirements.
Microsoft maintains SOC 2 Type II reports and ISO/IEC 27001, and PCI DSS coverage for applicable in-scope Azure services.
Technical safeguards support HIPAA-regulated use. Readiness depends on deployment, configuration, applicable agreements, and customer practices.
AI processing runs through the configured provider. Access may use a customer-owned account or a ChatBeacon-managed cloud configuration. Applicable provider data-use terms apply.
Enterprise SSO through Microsoft Entra ID, supported by role-based permissions and administrative access controls.
Deploy ChatBeacon within customer-controlled infrastructure for direct authority over hosting, data location, network access, and operational policies.
ChatBeacon Cloud and Dedicated Private Cloud services are hosted on Microsoft Azure. Microsoft maintains the audits, certifications, and attestations applicable to the Azure services and regions in scope for each deployment. These assurances cover Microsoft infrastructure and do not constitute a separate certification of ChatBeacon.
Microsoft publishes current audit reports and certificates through the Service Trust Portal. For application-level security reviews, ChatBeacon provides a security overview, architecture and data-flow documentation, and security questionnaire support.
Microsoft Azure compliance offerings →Physical security, hardware lifecycle, network fabric, hypervisor, and platform services are operated by Microsoft under the certifications above. Physical access to datacenters is Microsoft-controlled and audited.
Enterprise customers can deploy ChatBeacon in a dedicated Azure environment with isolated application and database resources, deployment-specific configuration, and an architecture review before go-live.
Deployments are provisioned in the Azure region agreed with your team, so conversation data is processed and stored in that geography. Region selection is confirmed as part of onboarding.
Azure platform network controls, TLS-terminated public endpoints, segmented application and database tiers, and administrative access restricted to authorized ChatBeacon operations personnel.
ChatBeacon installs on customer-controlled Windows Server, IIS, and Microsoft SQL Server. The customer owns the perimeter, the database, backups, and the patching schedule. No separate ChatBeacon-hosted conversation database is required.
Microsoft secures the underlying cloud infrastructure. ChatBeacon secures the application and its operations. Customers control access, configuration, retention, and integrations. Responsibilities are documented by deployment.
Visitor widget, operator console, admin portal, and API traffic are carried over TLS-protected connections. The enforced minimum protocol version and cipher configuration for your deployment can be confirmed during security review.
Azure-hosted deployments rely on Azure platform encryption for database and storage services, with Microsoft-managed keys by default. On-premises deployments use the customer's own SQL Server and disk encryption and key management.
Conversation and transcript retention is configurable, so you can hold records for the period your policy requires and no longer. On-premises customers additionally control database, archival, and backup retention.
Transcripts and account data can be exported and deleted to support data-subject requests and records-management obligations under GDPR, UK GDPR, and CCPA/CPRA.
Workflow and form configuration can limit what visitors are asked to provide, reducing unnecessary capture of sensitive information in the transcript. Payment card data should never be collected in chat.
Your conversation data remains yours. SmartMax processes it only to provide ChatBeacon and does not sell it or use it to train ChatBeacon AI models. Configured AI providers process data under their applicable terms.
Microsoft and Google sign-in are supported for the applicable ChatBeacon applications, with Microsoft Entra ID enterprise SSO available for eligible licensed configurations. Availability depends on application, deployment, and licensing.
When ChatBeacon is connected to your identity provider, your existing multifactor (MFA), device, and conditional-access policies govern agent and administrator sign-in. No parallel policy set to maintain.
Agent, supervisor, and administrator capabilities are assigned by role, limiting access to transcripts, configuration, reporting, and administrative controls according to job responsibilities.
Administrative and operational activity is logged to support traceability, supervisory review, and security investigations. Available log scope and export options vary by deployment and configuration.
Co-browse and screen-sharing sessions are initiated or approved by the visitor, limited to the active session, and can be configured to mask designated page fields from the agent’s view.
Access to production environments is limited to authorized operations and support personnel, granted for a documented business need, and removed when no longer required.
Changes undergo peer review and testing before release. Development and production environments are separated, and production customer data is not used for development.
Platform and dependency updates are applied on an ongoing basis in ChatBeacon-managed environments. On-premise customers receive official update packages and control their maintenance schedules.
Reported and detected vulnerabilities are evaluated by severity and addressed through scheduled releases or out-of-band fixes when warranted.
ChatBeacon-managed environments are monitored for availability, operational health, and error conditions, with alerts routed to authorized operations personnel.
Suspected security vulnerabilities can be reported to SmartMax with sufficient technical detail for investigation and reproduction. Researchers must not access, modify, retain, or disclose customer data.
Security events are investigated, contained, and remediated. Affected customers are notified as required by contract or law using established escalation contacts.
ChatBeacon supports customer-owned and ChatBeacon managed AI provider configurations. The selected configuration determines credentials, billing, provider-level data settings, and outbound data flows. AI processing follows the configured provider and its applicable data-use terms.
SmartMax does not use customer conversations to train ChatBeacon AI models. AI provider data use is governed by the selected service, account configuration, and applicable provider terms.
AI responses are grounded in customer-approved instructions, knowledge sources, domains, websites, and configured vector-store content. Knowledge can be assigned and scoped by workflow.
System instructions, approved topics, moderation rules, permitted actions, and escalation conditions provide policy enforcement for each workflow and reduce off-policy or unsupported responses.
When a conversation reaches a configured boundary or escalation condition, ChatBeacon transfers it to a live agent with available context so sensitive or high-risk cases reach a person.
When AI is enabled, only the content required to generate a response is sent to the configured AI provider. Disabling AI stops this provider-directed processing for AI response generation.
AI workflows that may process PHI require a HIPAA-eligible provider configuration and an applicable BAA. Deployment, data flows, and responsibilities are reviewed before PHI processing is enabled.
ChatBeacon supports HIPAA-supporting deployments for organizations handling protected health information (PHI) through technical safeguards, flexible deployment options, and documented responsibility boundaries.
Each environment is reviewed for its intended workflows, applicable BAAs, provider eligibility, access controls, retention settings, and customer administrative practices before PHI processing is enabled.
HIPAA-supporting deployments, PHI workflow reviews, applicable BAA requirements, and dedicated private cloud or on-premise hosting for patient-facing conversations.
Audit logging, retention controls, enterprise identity, and dedicated infrastructure for banks, credit unions, and insurers subject to security and examiner review.
Eligible Azure services and regions with government-focused authorizations, on-premise deployment, and documented data flows for agency review.
Controls for sensitive student information, retention limits, and role-based access across admissions, IT help desks, and student services.
Co-browse field masking, configurable data collection, and controls designed to reduce the collection of payment card data in chat transcripts.
Regional Azure hosting, a Data Processing Addendum, documented processing locations, and configurable data controls to support GDPR and UK GDPR programs.
ChatBeacon-managed deployments use Azure redundancy across compute, storage, and networking within the selected region.
Managed deployments are backed up on a defined schedule, with restore procedures documented for the selected architecture. On-premise customers control backup design, retention, and testing.
Recovery objectives and continuity procedures are defined according to the selected deployment model and documented during the solution and security review.
Support coverage, severity levels, escalation paths, and response expectations are defined in the applicable service agreement.
Planned maintenance for managed deployments is coordinated according to the selected architecture and service agreement. On-premise customers control their own maintenance windows.
Availability targets and service-level commitments are defined for the selected deployment and documented in the applicable service agreement.
Tell us the scope of your assessment, and we will provide the documentation relevant to your review. Detailed architecture and customer-specific materials are provided under an NDA.
Bring your questionnaire, architecture requirements, and review scope. We will help your security, privacy, and procurement teams evaluate the deployment options, responsibility boundaries, and controls relevant to your environment.
ChatBeacon Cloud and Dedicated Private Cloud are hosted on Microsoft Azure. Microsoft maintains a SOC 2 Type II attestation for applicable in-scope Azure services supporting these deployments. SmartMax provides a security overview, architecture and data-flow documentation, and questionnaire support for application-level vendor reviews.
Microsoft’s compliance portfolio for Azure includes SOC 1, SOC 2 Type II, SOC 3, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, PCI DSS, HITRUST, and FedRAMP. Applicability depends on the Azure services, region, and architecture selected for each ChatBeacon deployment.
ChatBeacon supports HIPAA-supporting deployments through encryption, role-based access, audit logging, configurable retention, and dedicated private cloud or on-premise options. Hosted deployments can use HIPAA-eligible Azure services. Architecture, configuration, applicable BAAs, AI-provider eligibility, and customer safeguards are reviewed for each deployment handling PHI.
ChatBeacon Cloud and Dedicated Private Cloud store and process conversation data in the Azure region selected for the deployment. Dedicated Private Cloud uses isolated application and database resources. On-Premise deployments store conversation data in the customer’s Microsoft SQL Server within its controlled environment.
Yes. Traffic between browsers, agents, and ChatBeacon services is protected with TLS. Data at rest in Azure-hosted deployments uses Azure platform encryption for storage and database services. On-premise customers control encryption and key management within their environments.
No. SmartMax does not use customer conversations to train ChatBeacon AI models. When AI is enabled, data use is governed by the selected provider configuration, account settings, and applicable provider terms.
Yes. ChatBeacon can be deployed on customer-controlled Windows Server, IIS, and Microsoft SQL Server infrastructure. On-premise deployments keep conversation records within the customer’s environment unless an approved external service, such as an AI provider, is enabled.
ChatBeacon supports Microsoft and Google sign-in for applicable applications. Microsoft Entra ID enterprise SSO is available for eligible licensed configurations. MFA and conditional-access policies are enforced through the connected identity provider.
Yes. ChatBeacon provides configurable retention, data export, deletion, and access controls, offers a Data Processing Addendum, and supports regional Azure hosting. Each customer remains responsible for how it configures and uses the platform under applicable privacy requirements.
A security overview, architecture and data-flow documentation, deployment-specific shared-responsibility documentation, a Data Processing Addendum, subprocessor information, AI governance and data-handling documentation, and support completing security questionnaires. Some materials are provided under NDA.