Trust Center
OverviewDeployment & DataService Privacy NoticeAI GovernanceSecurity Assurance
Security assurance

Enterprise security from
certified Microsoft Azure to on-premise

ChatBeacon cloud and dedicated private cloud services are hosted on Microsoft Azure. Microsoft maintains certifications, attestations, and authorizations for applicable Azure services, including SOC 2, ISO/IEC 27001, PCI DSS, and FedRAMP. These assurances apply to Microsoft Azure infrastructure and do not represent a separate certification of ChatBeacon.

Depending on deployment and configuration, ChatBeacon supports encryption in transit, enterprise identity integration, role-based access, audit logging, configurable retention, and customer-controlled AI connectivity. Organizations can deploy ChatBeacon in the cloud, in a dedicated private cloud, or on-premise according to their security, data-control, and operational requirements.

SOC 2 Type II via Microsoft Azure
ISO/IEC 27001 via Microsoft Azure
HIPAA-supporting deployments
TLS in transit, encrypted at rest
Dedicated private cloud
On-premise deployment
Customer-owned AI account

Security at a glance

Hosting
Microsoft Azure

Cloud and dedicated private cloud deployments with customer-selected Azure regions to support data residency and operational requirements.

Attestations
SOC 2 Type II

Microsoft maintains SOC 2 Type II reports and ISO/IEC 27001, and PCI DSS coverage for applicable in-scope Azure services.

Healthcare
HIPAA-ready

Technical safeguards support HIPAA-regulated use. Readiness depends on deployment, configuration, applicable agreements, and customer practices.

AI data
AI provider

AI processing runs through the configured provider. Access may use a customer-owned account or a ChatBeacon-managed cloud configuration. Applicable provider data-use terms apply.

IDENTITY AND ACCESS
Microsoft Entra ID

Enterprise SSO through Microsoft Entra ID, supported by role-based permissions and administrative access controls.

DEPLOYMENT
On-premise control

Deploy ChatBeacon within customer-controlled infrastructure for direct authority over hosting, data location, network access, and operational policies.

Certifications & attestations

Certified infrastructure, clearly attributed

ChatBeacon Cloud and Dedicated Private Cloud services are hosted on Microsoft Azure. Microsoft maintains the audits, certifications, and attestations applicable to the Azure services and regions in scope for each deployment. These assurances cover Microsoft infrastructure and do not constitute a separate certification of ChatBeacon.

Framework
Held by
What it covers
SOC 1, SOC 2 Type II, SOC 3
Microsoft Azure
Independent examination of Microsoft's security, availability, and confidentiality controls for in-scope Azure services. The datacenters, hypervisor, storage, and platform services hosting ChatBeacon.
ISO/IEC 27001
Microsoft Azure
Information security management system certification for Azure infrastructure and operations.
ISO/IEC 27017 & 27018
Microsoft Azure
Cloud-specific security controls and protection of personally identifiable information in public cloud.
ISO/IEC 27701
Microsoft Azure
Privacy information management relevant to GDPR-aligned processing commitments at the Azure infrastructure layer.
PCI DSS
Microsoft Azure
Azure's attestation of compliance for in-scope services. ChatBeacon is not a payment processor and cardholder data should not be entered into chat.
FedRAMP, HITRUST CSF
Microsoft Azure
Authorizations and certifications available for eligible Azure services and regions. Applicability depends on the deployment architecture selected for your environment.
HIPAA / HITECH
Shared responsibility
ChatBeacon supports HIPAA-supporting deployments for handling PHI with encryption, access controls, audit logging, configurable retention, and eligible Azure services. HIPAA/HITECH readiness depends on deployment, configuration, agreements, and customer practices.
GDPR, UK GDPR, CCPA/CPRA
Contractual and operational
Supported through a Data Processing Addendum, regional hosting choice, configurable retention, and data export and deletion controls.

Microsoft publishes current audit reports and certificates through the Service Trust Portal. For application-level security reviews, ChatBeacon provides a security overview, architecture and data-flow documentation, and security questionnaire support.

Microsoft Azure compliance offerings →
Infrastructure & hosting

Where ChatBeacon runs

Microsoft Azure datacenters

Physical security, hardware lifecycle, network fabric, hypervisor, and platform services are operated by Microsoft under the certifications above. Physical access to datacenters is Microsoft-controlled and audited.

Dedicated private cloud

Enterprise customers can deploy ChatBeacon in a dedicated Azure environment with isolated application and database resources, deployment-specific configuration, and an architecture review before go-live.

Regional data residency

Deployments are provisioned in the Azure region agreed with your team, so conversation data is processed and stored in that geography. Region selection is confirmed as part of onboarding.

Network protection

Azure platform network controls, TLS-terminated public endpoints, segmented application and database tiers, and administrative access restricted to authorized ChatBeacon operations personnel.

On-premise deployment

ChatBeacon installs on customer-controlled Windows Server, IIS, and Microsoft SQL Server. The customer owns the perimeter, the database, backups, and the patching schedule. No separate ChatBeacon-hosted conversation database is required.

Separation of duties

Microsoft secures the underlying cloud infrastructure. ChatBeacon secures the application and its operations. Customers control access, configuration, retention, and integrations. Responsibilities are documented by deployment.

Data protection

Encryption, retention, and deletion

In transit

Visitor widget, operator console, admin portal, and API traffic are carried over TLS-protected connections. The enforced minimum protocol version and cipher configuration for your deployment can be confirmed during security review.

At rest

Azure-hosted deployments rely on Azure platform encryption for database and storage services, with Microsoft-managed keys by default. On-premises deployments use the customer's own SQL Server and disk encryption and key management.

Retention controls

Conversation and transcript retention is configurable, so you can hold records for the period your policy requires and no longer. On-premises customers additionally control database, archival, and backup retention.

Export and deletion

Transcripts and account data can be exported and deleted to support data-subject requests and records-management obligations under GDPR, UK GDPR, and CCPA/CPRA.

Sensitive data handling

Workflow and form configuration can limit what visitors are asked to provide, reducing unnecessary capture of sensitive information in the transcript. Payment card data should never be collected in chat.

Ownership

Your conversation data remains yours. SmartMax processes it only to provide ChatBeacon and does not sell it or use it to train ChatBeacon AI models. Configured AI providers process data under their applicable terms.

Identity & access control

Who can get in, and what they can do

Enterprise single sign-on

Microsoft and Google sign-in are supported for the applicable ChatBeacon applications, with Microsoft Entra ID enterprise SSO available for eligible licensed configurations. Availability depends on application, deployment, and licensing.

MFA and conditional access

When ChatBeacon is connected to your identity provider, your existing multifactor (MFA), device, and conditional-access policies govern agent and administrator sign-in. No parallel policy set to maintain.

Role-based permissions

Agent, supervisor, and administrator capabilities are assigned by role, limiting access to transcripts, configuration, reporting, and administrative controls according to job responsibilities.

Audit & activity logging

Administrative and operational activity is logged to support traceability, supervisory review, and security investigations. Available log scope and export options vary by deployment and configuration.

Co-browse consent

Co-browse and screen-sharing sessions are initiated or approved by the visitor, limited to the active session, and can be configured to mask designated page fields from the agent’s view.

ChatBeacon personnel access

Access to production environments is limited to authorized operations and support personnel, granted for a documented business need, and removed when no longer required.

Application & platform security

How ChatBeacon is built and maintained

Secure development

Changes undergo peer review and testing before release. Development and production environments are separated, and production customer data is not used for development.

Patching and dependencies

Platform and dependency updates are applied on an ongoing basis in ChatBeacon-managed environments. On-premise customers receive official update packages and control their maintenance schedules.

Vulnerability management

Reported and detected vulnerabilities are evaluated by severity and addressed through scheduled releases or out-of-band fixes when warranted.

Security monitoring

ChatBeacon-managed environments are monitored for availability, operational health, and error conditions, with alerts routed to authorized operations personnel.

Report a vulnerability

Suspected security vulnerabilities can be reported to SmartMax with sufficient technical detail for investigation and reproduction. Researchers must not access, modify, retain, or disclose customer data.

Incident response

Security events are investigated, contained, and remediated. Affected customers are notified as required by contract or law using established escalation contacts.

AI data handling

How ChatBeacon handles AI data

ChatBeacon supports customer-owned and ChatBeacon managed AI provider configurations. The selected configuration determines credentials, billing, provider-level data settings, and outbound data flows. AI processing follows the configured provider and its applicable data-use terms.

No training on conversations

SmartMax does not use customer conversations to train ChatBeacon AI models. AI provider data use is governed by the selected service, account configuration, and applicable provider terms.

Knowledge you approve

AI responses are grounded in customer-approved instructions, knowledge sources, domains, websites, and configured vector-store content. Knowledge can be assigned and scoped by workflow.

Governed workflows

System instructions, approved topics, moderation rules, permitted actions, and escalation conditions provide policy enforcement for each workflow and reduce off-policy or unsupported responses.

Controlled human handoff

When a conversation reaches a configured boundary or escalation condition, ChatBeacon transfers it to a live agent with available context so sensitive or high-risk cases reach a person.

Outbound data flows

When AI is enabled, only the content required to generate a response is sent to the configured AI provider. Disabling AI stops this provider-directed processing for AI response generation.

PHI and regulated content

AI workflows that may process PHI require a HIPAA-eligible provider configuration and an applicable BAA. Deployment, data flows, and responsibilities are reviewed before PHI processing is enabled.

HIPAA readiness

HIPAA-supporting deployments with clear responsibilities

ChatBeacon supports HIPAA-supporting deployments for organizations handling protected health information (PHI) through technical safeguards, flexible deployment options, and documented responsibility boundaries.

Each environment is reviewed for its intended workflows, applicable BAAs, provider eligibility, access controls, retention settings, and customer administrative practices before PHI processing is enabled.

Discuss your healthcare deployment →

What ChatBeacon provides

  • TLS-protected connections and encryption at rest for Azure-hosted deployments
  • Microsoft Entra ID SSO with identity-provider MFA
  • Role-based access controls
  • Audit and activity logging
  • Configurable retention, export, and deletion
  • Cloud, dedicated private cloud, and on-premise deployment options
  • Field masking and configurable data collection

What your deployment needs

  • HIPAA-eligible services for hosted deployments
  • Applicable BAAs when required
  • A HIPAA-eligible AI provider and applicable BAA if AI will process PHI
  • Appropriate access, retention, and logging configuration
  • Workforce policies, training, and access reviews
  • Documented review of PHI workflows and data flows
Deployment & Data

Three deployment models, clear security responsibilities

Control
ChatBeacon Cloud
Dedicated private CLOUD
On-premise
Infrastructure
Microsoft Azure,
ChatBeacon-managed
Dedicated Azure resources, ChatBeacon-managed
Customer servers and network
Infrastructure
assurance
Microsoft Azure certifications and attestations for in-scope services
Microsoft Azure certifications and attestations for in-scope services
Customer-controlled infrastructure, controls, and audits
Database
ChatBeacon-managed
Isolated database per customer
Customer-managed Microsoft SQL Server
Updates
Applied by ChatBeacon
Coordinated with your team
Applied on your maintenance schedule
Best fit
Teams seeking rapid deployment on Azure-hosted infrastructure
Organizations requiring isolated Azure resources and deployment-specific architecture
Organizations keeping data within their own controlled perimeter
External AI
Optional; customer-owned or ChatBeacon-managed provider configuration
Optional; configured for the customer’s environment
Optional; customer-approved outbound provider connectivity
Regulated industries

Built for rigorous security reviews

Healthcare

HIPAA-supporting deployments, PHI workflow reviews, applicable BAA requirements, and dedicated private cloud or on-premise hosting for patient-facing conversations.

Financial services

Audit logging, retention controls, enterprise identity, and dedicated infrastructure for banks, credit unions, and insurers subject to security and examiner review.

Government and public sector

Eligible Azure services and regions with government-focused authorizations, on-premise deployment, and documented data flows for agency review.

Higher education

Controls for sensitive student information, retention limits, and role-based access across admissions, IT help desks, and student services.

Retail ecommerce

Co-browse field masking, configurable data collection, and controls designed to reduce the collection of payment card data in chat transcripts.

Multinational operations

Regional Azure hosting, a Data Processing Addendum, documented processing locations, and configurable data controls to support GDPR and UK GDPR programs.

Availability & continuity

Availability and recovery built around your deployment

Platform resilience

ChatBeacon-managed deployments use Azure redundancy across compute, storage, and networking within the selected region.

Backups

Managed deployments are backed up on a defined schedule, with restore procedures documented for the selected architecture. On-premise customers control backup design, retention, and testing.

Recovery planning

Recovery objectives and continuity procedures are defined according to the selected deployment model and documented during the solution and security review.

Support coverage

Support coverage, severity levels, escalation paths, and response expectations are defined in the applicable service agreement.

Maintenance coordination

Planned maintenance for managed deployments is coordinated according to the selected architecture and service agreement. On-premise customers control their own maintenance windows.

Availability commitments

Availability targets and service-level commitments are defined for the selected deployment and documented in the applicable service agreement.

Vendor assessment

Documentation for your security review

Tell us the scope of your assessment, and we will provide the documentation relevant to your review. Detailed architecture and customer-specific materials are provided under an NDA.

Security overview
On request
Architecture and data-flow diagrams
On request / NDA
Microsoft Azure audit reports and certificates
Microsoft Service Trust Portal
Data Processing Addendum
On request
Subprocessor and connected-service information
On request
AI governance and data-handling documentation
On request
Security questionnaires (CAIQ, SIG, and custom)
On request
Service Privacy Notice and Terms of Service
Public

Talk to the team that answers the hard questions

Bring your questionnaire, architecture requirements, and review scope. We will help your security, privacy, and procurement teams evaluate the deployment options, responsibility boundaries, and controls relevant to your environment.

Frequently asked questions

Security questions, answered directly

How does SOC 2 apply to ChatBeacon hosting?

ChatBeacon Cloud and Dedicated Private Cloud are hosted on Microsoft Azure. Microsoft maintains a SOC 2 Type II attestation for applicable in-scope Azure services supporting these deployments. SmartMax provides a security overview, architecture and data-flow documentation, and questionnaire support for application-level vendor reviews.

Which Azure certifications and attestations support ChatBeacon hosting?

Microsoft’s compliance portfolio for Azure includes SOC 1, SOC 2 Type II, SOC 3, ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 27701, PCI DSS, HITRUST, and FedRAMP. Applicability depends on the Azure services, region, and architecture selected for each ChatBeacon deployment.

How does ChatBeacon support HIPAA-supporting deployments?

ChatBeacon supports HIPAA-supporting deployments through encryption, role-based access, audit logging, configurable retention, and dedicated private cloud or on-premise options. Hosted deployments can use HIPAA-eligible Azure services. Architecture, configuration, applicable BAAs, AI-provider eligibility, and customer safeguards are reviewed for each deployment handling PHI.

Where is ChatBeacon data stored?

ChatBeacon Cloud and Dedicated Private Cloud store and process conversation data in the Azure region selected for the deployment. Dedicated Private Cloud uses isolated application and database resources. On-Premise deployments store conversation data in the customer’s Microsoft SQL Server within its controlled environment.

Is ChatBeacon data encrypted?

Yes. Traffic between browsers, agents, and ChatBeacon services is protected with TLS. Data at rest in Azure-hosted deployments uses Azure platform encryption for storage and database services. On-premise customers control encryption and key management within their environments.

Does ChatBeacon use customer conversations to train AI models?

No. SmartMax does not use customer conversations to train ChatBeacon AI models. When AI is enabled, data use is governed by the selected provider configuration, account settings, and applicable provider terms.

Can ChatBeacon run on our own servers?

Yes. ChatBeacon can be deployed on customer-controlled Windows Server, IIS, and Microsoft SQL Server infrastructure. On-premise deployments keep conversation records within the customer’s environment unless an approved external service, such as an AI provider, is enabled.

What single sign-on options does ChatBeacon support?

ChatBeacon supports Microsoft and Google sign-in for applicable applications. Microsoft Entra ID enterprise SSO is available for eligible licensed configurations. MFA and conditional-access policies are enforced through the connected identity provider.

Does ChatBeacon support GDPR and CCPA obligations?

Yes. ChatBeacon provides configurable retention, data export, deletion, and access controls, offers a Data Processing Addendum, and supports regional Azure hosting. Each customer remains responsible for how it configures and uses the platform under applicable privacy requirements.

What security documentation can ChatBeacon provide for a vendor review?

A security overview, architecture and data-flow documentation, deployment-specific shared-responsibility documentation, a Data Processing Addendum, subprocessor information, AI governance and data-handling documentation, and support completing security questionnaires. Some materials are provided under NDA.

Last updated: August 25, 2026