Security at Logicl.
How Logicl protects customer enquiry data, separates tenant work and keeps customer-facing AI actions governed.
Last updated: 20 August 2026
Customer data and tenant separation
- Protected workspace access requires a server-validated user session and trusted organisation scope.
- Customer, contact, enquiry, interaction, settings and audit records are scoped by organisation in application persistence.
- Credentials are held in server-side environment or provider secret stores; secret values are not intended for browser variables or customer records.
- Security headers include HSTS, content-type, framing, referrer and permissions protections.
Governed AI actions
Deterministic controls keep authority outside the AI model. High-impact outbound actions are disabled by default and general live-action gates do not permit automatic execution.
Where a narrowly controlled provider action is enabled, it requires authenticated organisation context, explicit human approval, provider readiness, usage controls and audit evidence.
Infrastructure and providers
The current service path uses managed providers for web hosting, authentication and data services, phone-bridge hosting, communications, speech processing and model inference. The active provider list and carefully qualified roles are published on the Subprocessors page.
Provider regions, retention and contractual terms require deployment-specific verification before a contractual commitment is made.
Software development and change control
Changes use scoped branches, pull requests, automated builds, tests, type checking and repository guardrails. Production merge authority remains with an authorised human reviewer.
Dependency updates are monitored automatically. Material authentication, tenant, provider and governance changes receive focused tests and review.
Incident response and resilience
Logicl maintains a lean incident procedure covering detection, containment, credential rotation, tenant impact assessment, evidence preservation, recovery, notification assessment and post-incident improvement.
The service uses managed infrastructure and health diagnostics. Backup configuration, recovery objectives and restore evidence are confirmed for a deployment before any specific resilience commitment is made.
Privacy, retention and assurance status
Customer conversations are not automatically promoted into model training or trusted tenant knowledge. Retention and deletion remain category- and deployment-specific; not every export or deletion workflow is automated.
Logicl maintains an internal security control and assurance programme. Controls are documented and mapped against common assurance expectations, but Logicl is not independently audited under SOC 2 and is not certified to ISO 27001.
Report a suspected vulnerability or security incident to security@logicl.com.au. Please omit secrets and unnecessary personal information from the initial report.
Related trust pages
Questions or concerns? Use the dedicated privacy and security contact path.
Contact privacy & security