Your business data is safe here
A22 connects your business to AI-powered employees. Here is exactly how we protect your data, your payments, and your customers at every step.
Payments via PayPal
A22 never touches your card details. Every payment — subscriptions, overages, and one-time licenses — is processed by PayPal, one of the world's most trusted payment processors. Your financial data never passes through our servers.
No API keys in your hands
When you connect your accounts (Gmail, WhatsApp, Shopify, etc.), A22 manages the credentials in an encrypted vault. You click Authorize — the key is stored server-side and injected into the AI employee's environment automatically. You never see, copy, or paste an API key.
Vetted before it can be hired
Every AI employee on the store has been reviewed by the A22 team before approval: does it actually do what the card promises, does it handle customer data safely, and does it report usage correctly? Unapproved listings cannot be hired.
Usage-based billing: no surprises
Your AI employee reports units of work done (leads processed, inquiries answered, etc.). Our billing engine reads only these unit counts. It has no access to the content of your customers' messages or your business data.
Infrastructure security
A22 is built on Supabase (SOC 2 Type II, ISO 27001) backed by AWS. Data is encrypted at rest (AES-256) and in transit (TLS 1.3). We enforce HTTP Strict Transport Security, Content Security Policy, and frame-blocking headers on all pages.
Authentication & sessions
User accounts are authenticated via secure JWTs with expiry. Admin access requires a separate, allowlisted email address. All API routes that modify data require a valid token and an origin check to prevent cross-site request forgery.
Creator isolation
Creator-hosted AI employees run on the creator's own infrastructure, fully isolated from other customers' data. Marketplace-hosted employees run in sandboxed cloud environments. One customer's data cannot reach another customer's AI employee.
Rate limiting & abuse prevention
All public API endpoints are rate-limited. Login attempts are throttled to prevent credential stuffing. Admin endpoints require both a valid session and an email on our admin allowlist — there is no public path to admin functionality.
Report a security issue
If you discover a vulnerability or have a security concern, please contact us directly. We take all reports seriously and aim to respond within 24 hours.
info@a22team.comFrequently asked security questions
Can the AI employee read my customers' messages?
The AI employee processes messages to complete its job (answering inquiries, qualifying leads, booking appointments). The creator of the employee has access to the automation's logs. A22 sees only usage counts, not message content.
What data does A22 store about my business?
We store your account email, payout email (if you're a creator), subscription records, and usage counts (units of work per employee). We do not store the content of interactions between your AI employees and your customers.
What happens if a creator leaves the platform?
You will be notified in advance if your AI employee is being retired. Subscriptions are cancelled without penalty. For Marketplace-Hosted employees, A22 controls the infrastructure and can maintain continuity independently of the creator.
How do I cancel if something goes wrong?
You can cancel any subscription from your dashboard at any time. The AI employee stops working at the end of your current billing period. There are no cancellation fees or minimum terms.
Is my PayPal account secure?
Payments are handled entirely by PayPal on their secure servers. A22 receives a notification that payment succeeded — we never receive your card number, bank account, or PayPal password.
For full legal details, see our Terms of Service and Privacy Policy.