Skip to main content

Authenticated vs. Guest Access Controls

Everest enforces distinct capability sets for authenticated and guest sessions. Guest users receive public knowledge answers and limited secure lookups, such as case status and order status, gated behind verification forms. Authenticated sessions unlock account-bound actions such as device management and case updates. Capability sets are rule-based and configured per flow and per action, so administrators define exactly which steps require which access level.

Data Residency and Compliance

  • Data residency options in the US and the EU, selected per tenant.
  • SOC 2 Type II attested.
  • GDPR compliant, with a Data Processing Agreement (DPA) available.
  • All data is encrypted in transit and at rest.

PII Handling and Masking

Everest detects and masks PII, including email addresses, phone numbers, and card numbers, in logs, transcripts, and any data used for training. Masking applies before data is persisted, so raw PII does not enter downstream stores. Retention periods are configurable per data class, allowing shorter retention for sensitive data than for operational records.

Role-Based Access for Admin Console

The admin console uses granular role-based access control with four built-in roles:
  • Author: builds flows and manages knowledge content.
  • Reviewer: approves promotions between environments.
  • Admin: full configuration access, including users, integrations, and security settings.
  • Analyst: read-only access to analytics and reporting.

Audit Log for Compliance

Everest maintains an append-only, tamper-evident audit trail covering every bot action, API call, routing decision, and admin change. Each entry records the actor, timestamp, and affected resource. Logs are exportable as CSV or JSON, or streamed to a SIEM. Default retention is 13 months and is configurable per tenant.