Legal

Version 2026-08-24-v1 · Last updated August 24, 2026 · Reviewed annually

Information Security Policy

High iQ ("Company," "we," "us," or "our") operates an AI-powered sales, communication, and customer-relationship platform (the "Platform"). This Information Security Policy describes the administrative, technical, and physical safeguards we maintain to protect the confidentiality, integrity, and availability of the information entrusted to us by our customers and their contacts.

This policy is published so that customers, integration partners, and prospective customers can evaluate our security programme. It describes our practices as of the effective date above. It does not create contractual obligations beyond those set out in our Services Agreement, and in the event of a conflict, the Services Agreement controls.

1. Scope and Ownership

Scope. This policy applies to all systems, applications, networks, cloud services, endpoints, and data used to deliver or support the Platform, and to all personnel with access to them, including employees, officers, contractors, and temporary staff.

Ownership. Our Compliance Director owns this policy and the security programme. Our Chief Technology Officer owns technical implementation of the controls described here. Both roles report to the Founder.

Review cadence. This policy is reviewed at least annually and after any material change to our architecture, subprocessors, or regulatory obligations. Versions are recorded at the top of this document.

Exceptions. Any deviation from this policy requires documented approval from the Compliance Director and the CTO, must state a business justification, a compensating control, and an expiry date, and is revisited at each review.

2. Risk Management

We maintain a risk-based programme rather than a checkbox one. We perform a documented risk assessment at least annually and when we introduce a material new system, subprocessor, or data flow. Risks are recorded with an owner, a severity rating, and a remediation plan; high-severity items are tracked to closure.

Prospective vendors and subprocessors are reviewed before onboarding for the data they will touch, their security posture and published attestations, their breach-notification commitments, and their contractual data-protection terms. Vendors that will process customer content are subject to written confidentiality and data-protection obligations.

3. Access Control

  • Least privilege. Access is granted only as needed to perform a role, and is scoped to the minimum data and systems required.
  • Unique accounts. Every user has an individually attributable account. Shared or generic logins are prohibited for administrative systems.
  • Multi-factor authentication. MFA is required on administrative and production systems, including our cloud provider, source control, and secret management, and is enforced for privileged internal accounts.
  • Role-based permissions. Within the Platform, account owners configure the permissions of their own team members. Our internal roles are separated between support, engineering, and administrative functions.
  • Access review. Privileged access is reviewed at least quarterly and adjusted or revoked where it is no longer required.
  • Offboarding. Access for departing personnel is revoked promptly, with a target of one business day from separation.
  • Support access. Authorized personnel may access a customer account to diagnose issues or provide support. Such access is logged.

4. Authentication and Secrets Management

Application credentials, API keys, and integration tokens are stored in a managed secret vault with restricted access, never in source code, tickets, chat, or spreadsheets. Secrets are rotated on a periodic basis and immediately upon suspected exposure or the departure of anyone with access. Passwords for internal systems must meet complexity requirements and are managed through a password manager.

5. Data Protection

Encryption. Data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest using industry-standard algorithms provided by our managed cloud and database services.

Tenant isolation. Each customer account's data is logically isolated. Row-level access controls are enforced at the database layer so that queries are constrained to the requesting account, in addition to application-level authorization checks.

Classification. We treat customer contact records, call recordings, transcripts, message content, and credentials as confidential data subject to the strictest handling. Aggregated and de-identified statistics that do not identify any individual are treated as internal data.

Retention and deletion. Retention follows the terms of our Privacy Policy and the Services Agreement. Customers may delete individual records within the Platform. On account closure, we delete or de-identify account data within a commercially reasonable period, except where retention is required for legal, regulatory, billing-dispute, or backup and archival purposes.

Production data in non-production environments. Live customer data is not used in development or testing environments except where strictly necessary to reproduce a reported defect, under the same access controls as production.

6. Application Security

  • Change management. Changes are made through version-controlled source, peer review, and automated checks before release. Production deployments are traceable to an author and a change record.
  • Environment separation. Development, preview, and production environments are separated, with distinct credentials and data stores.
  • Dependency management. Third-party dependencies are tracked and scanned for known vulnerabilities; identified issues are prioritized by severity and patched on a risk-based schedule.
  • Secure development practices. We follow common secure-coding practices for input validation, authentication and authorization checks on every server-side entry point, output encoding, and protection against injection and cross-site scripting.
  • Vulnerability remediation targets. Critical issues are targeted for remediation within 7 days of confirmation, high within 30 days, and medium or low on the next scheduled maintenance cycle, subject to available fixes from upstream providers.

7. Infrastructure and Network Security

The Platform runs on managed, reputable cloud infrastructure in the United States. We rely on the provider's physical security, redundancy, and network controls, and we configure our own workloads with hardened defaults, restricted inbound access, and provider-managed patching where available. Administrative interfaces are protected by MFA and restricted accounts. Application and infrastructure telemetry, including error monitoring and uptime checks, is collected to detect anomalies.

8. Endpoint and Workforce Security

Company and personnel devices used to access production systems or customer data must have full-disk encryption, automatic screen lock, current operating-system patches, and endpoint protection appropriate to the device. Personnel are subject to written confidentiality obligations, an acceptable-use standard, and background screening where permitted by law and appropriate to the role. Security awareness training, covering phishing, social engineering, credential hygiene, and incident reporting, is provided at hire and at least annually thereafter.

9. Logging, Monitoring, and Audit

We log authentication events, administrative and support access to customer accounts, privileged configuration changes, and application errors. Logs are retained for a period appropriate to their type and are access-restricted. Alerts are raised on error-rate anomalies and availability failures. Logs are reviewed during incident investigation and periodically as part of access review.

10. Incident Response

We maintain an incident response process covering detection, triage and severity classification, containment, eradication, recovery, and post-incident review.

  • Detection and reporting. All personnel are required to report suspected incidents immediately to the Compliance Director and CTO.
  • Severity. Incidents are classified by impact to confidentiality, integrity, and availability. Suspected unauthorized access to customer data is treated as high severity by default.
  • Containment and recovery. We isolate affected systems, revoke or rotate implicated credentials, and restore from known-good state where required.
  • Customer notification. Where we determine that a security incident has affected a customer's data, we will notify the affected customer without undue delay after confirmation, and in any event within the timeframes required by applicable law or our written agreement with that customer. Notifications describe what we know, what we are doing, and what the customer should do.
  • Post-incident review. Every high-severity incident results in a documented review with root cause, corrective actions, and owners.

11. Business Continuity and Disaster Recovery

Customer data is stored in managed database services with automated backups and point-in-time recovery available within the retention window offered by our provider. Restoration procedures are tested periodically. Our recovery objectives are targets, not guarantees: we target a recovery point objective (RPO) of 24 hours or better and a recovery time objective (RTO) of 24 hours or better for a full-service restoration event. Availability depends in part on upstream cloud, telephony, and model providers.

12. Third Parties and Subprocessors

We use subprocessors to deliver the Platform, including cloud hosting and database services, telephony and SMS carriers, voice and speech-processing providers, large language model providers, transactional and campaign email providers, payment processing, error monitoring, and analytics. Each is bound by confidentiality and data-protection obligations and is permitted to use data only to provide services to us. Payment card numbers are collected and stored by our payment processor, not by us. Categories of recipients are described further in our Privacy Policy.

13. AI and Communications Security

Call audio, transcripts, message content, and related context are transmitted to model and speech providers solely to produce outputs for the account that generated them. We do not permit our AI model providers to use customer content to train their general-purpose models.

Call recording and transcription can be configured or disabled at the account level. Recordings and transcripts inherit the same encryption, tenant isolation, access control, and retention treatment as all other customer content. AI outputs are probabilistic and are decision support, not a substitute for human review.

14. Compliance Posture

We design our controls with reference to widely used frameworks, including SOC 2 Trust Services Criteria and ISO/IEC 27001 control domains. We are not currently SOC 2 Type II certified or ISO/IEC 27001 certified, and we do not represent otherwise. We will update this section if and when an audit is completed.

Privacy rights under the CCPA/CPRA and comparable U.S. state laws are handled as described in our Privacy Policy. Telephony and messaging obligations, including the TCPA and state analogues, CAN-SPAM, applicable FCC rules, and A2P 10DLC carrier requirements, are addressed in our Services Agreement; the Platform provides compliance tooling such as automatic STOP and unsubscribe suppression and optional DNC and litigator screening, and our customers remain responsible for lawful use.

15. Customer Responsibilities

Security is shared. Customers are responsible for:

  • Safeguarding login credentials and enabling available account-security features.
  • Managing team membership, permissions, and prompt removal of departed users.
  • Configuring recording, messaging, and automation features in a manner lawful for their jurisdiction and use case.
  • Obtaining and documenting consent before contacting their leads and clients, and honoring opt-outs.
  • Reviewing AI outputs and campaign activity, and promptly notifying us of suspected unauthorized access.

16. Reporting a Vulnerability

We welcome good-faith reports from security researchers and partners. Email legal@highiq.io with a description of the issue, the affected component, and steps to reproduce. We will acknowledge receipt, investigate, and keep you informed of remediation.

We ask that researchers avoid accessing, modifying, or exfiltrating data that is not their own, avoid degrading service availability, and give us a reasonable period to remediate before public disclosure. We will not pursue action against researchers who act in good faith and within these guidelines.

17. No Guarantee

No method of transmission or storage is completely secure. The safeguards described here are designed to reduce risk to a commercially reasonable level; they are not a guarantee against every possible attack, failure, or misuse. Nothing in this policy expands the warranties, obligations, or liability set out in our Services Agreement.

18. Contact

High iQ

PO Box 607

Colorado Springs, CO 80901

legal@highiq.io