Point11
Book demo

Security

Last updated: July 22, 2026

Point11 is committed to protecting the security and privacy of our customers’ data. This page describes our security practices and infrastructure.

Infrastructure

The Point11 platform is hosted on Vercel, with managed Postgres (Neon) and Redis (Upstash). Application compute may run across multiple regions. Customer deployments may run in customer-controlled cloud environments under enterprise agreements.

  • Data encrypted in transit using TLS 1.2 or higher for all connections
  • Data encrypted at rest using AES-256 or equivalent
  • Multi-factor authentication required for all administrative access
  • Role-based access controls with least-privilege principles
  • Access to production systems restricted to authorized engineering personnel and reviewed regularly
  • Platform-level DDoS mitigation at the network edge
  • Separation between production and development environments

Data Handling

We do not use customer data to train, fine-tune, or improve AI models, and the third-party AI providers we route requests through are contractually restricted from training on it.

Customer data is retained while needed to provide the services and meet legal obligations. Customers may request deletion in writing; billing and other records may be retained as required.

Point11 does not directly process or store payment card data; payment processing is handled by PCI DSS-certified processors (Stripe). To discuss HIPAA requirements or other compliance needs, contact legal@point11.ai.

Practices

  • Automated vulnerability scanning and timely patching by severity
  • Security incidents affecting customer data are reported to affected customers without undue delay, as required by applicable law
  • Post-incident review and remediation for confirmed incidents
  • Security awareness training and confidentiality agreements for all personnel
  • Managed database recovery and multi-region application compute

Responsible Disclosure

If you discover a security vulnerability in Point11’s platform, please report it to support@point11.ai. Scope, safe harbor, and reporting guidance: vulnerability disclosure policy.

Due Diligence

Enterprise customers may request additional security documentation as part of procurement. Contact legal@point11.ai or your account representative.