A quick reference for evaluating K3X's security posture. For anything your security questionnaire needs beyond this page, contact us — we're happy to go deeper: [email protected].
Encryption
All data is encrypted in transit and at rest by default. Call recordings are stored encrypted as well.
Access control
Role-based permissions are built in: Owner, Administrator, Sales Manager, and Sales Representative ship out of the box, and custom roles let you define access that matches your team's structure.
Record scoping — roles can see all records or only assigned records.
Disable vs delete — disabling a member instantly cuts access while preserving the audit trail; deleting removes them from the org.
Enterprise controls (available on request)
Single sign-on (SSO)
Advanced access controls for tighter boundaries around who can access what
Data residency options for teams with regional requirements
Audit logs to track changes and access across your team
Contact us to enable any of these for your workspace.
Recordings and transcripts
Recordings and transcripts inherit the lead's access controls, are stored encrypted, and follow a configurable retention policy (from 30 days up to 7 years, or longer for Enterprise). Deleting a recording also deletes its transcript, and deletions are logged.
Your data through your accounts
Email sends through your own connected Gmail/Outlook mailbox — K3X never emails your leads from a K3X address. Payments are processed by Stripe; K3X never sees or stores card numbers.
Compliance features for messaging
Opt-out (STOP) handling, quiet-hours enforcement, consent record-keeping, and an exportable opt-out audit trail are built into the SMS stack — see the Messaging & Voice collection.
Security reviews
More detail lives at https://k3x.ai/security For questionnaires, DPAs, and subprocessor lists, email [email protected] and we'll get you what you need.
