> ## Documentation Index
> Fetch the complete documentation index at: https://sitegpt.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and compliance

> How SiteGPT protects your data, and the certifications behind it.

Security posture, certifications, and up-to-date policy documents live on
our trust portal: [trust.sitegpt.ai](https://trust.sitegpt.ai). This page
summarizes what matters day to day.

## Certifications and regulations

* **SOC 2 Type II**: SiteGPT is audited against SOC 2 Type II. Reports are
  available through the trust portal.
* **GDPR**: SiteGPT operates as a processor for the visitor data your
  chatbot handles, with GDPR-aligned processes for data subject requests
  and deletion.
* **HIPAA**: SiteGPT maintains a HIPAA compliance program. If your use case
  involves protected health information, contact
  [support@sitegpt.ai](mailto:support@sitegpt.ai) to discuss requirements
  and agreements before going live.

## How your data is handled

* **Your content stays yours.** Trained content is used to answer your
  chatbot's questions, and is not shared across customers.
* **Conversations and leads** are stored for your dashboard and are
  exportable and deletable by you: delete individual content, leads, and
  conversations in the dashboard, or the whole chatbot at once.
* **API tokens** are shown once at creation and stored hashed; scope them
  narrowly and rotate them from the
  [Agents page](/docs/developers/api-tokens-and-mcp).
* **Webhook tokens** are shared secrets that SiteGPT sends with every
  delivery so your endpoint can verify the sender. They stay visible in
  **Settings → Webhooks**; treat them like passwords and change them there
  if one leaks.
* **Sign-in is passwordless.** Email links avoid password reuse; access to
  your inbox is access to your account, so protect the inbox accordingly.

## For your visitors

* The widget collects what you configure it to collect: conversation
  messages, and contact details when you enable
  [lead collection](/docs/features/lead-collection) or pre-chat details.
* [Tracking events](/docs/developers/tracking-events) sent to your analytics
  carry ids and event names, not message content or contact details.
* Add your own terms in front of the chat with **Disclaimer Text** in
  [Appearance](/docs/features/appearance).

## Questionnaires and reviews

Running a vendor review? The trust portal has the current subprocessor
list, policies, and audit reports. For anything it does not answer, email
[support@sitegpt.ai](mailto:support@sitegpt.ai).
