Start free — AI from $9.99

No credit card. Live in 5 minutes.

Start
Skip to main content
Enterprise security · built in, not bolted on

Enterprise-grade security for agentic AI.

SSO and SAML, audit logs, and data controls that satisfy IT and compliance — without slowing your team down. Give agentic AI broad channel access with the guardrails your security review expects.

SSO & SAMLAudit logs & IP blocklistingRole-based accessGDPR & CCPA aligned

Built for teams that answer to security reviews.

app.floatchat.com · securitySecured

Single sign-on

SAML 2.0 · Okta, Azure AD, Google

Enforced · MFA required · JIT provisioning on
Role-based accessview · operate · manage · admin

Owner

full

Admin

manage

Agent

operate

Analyst

read

IP blocklist
10.0.0.0/8office · allow
198.51.100.24vpn · allow
203.0.113.9blocked
Audit logstreaming · immutable
m.webbexported audit log
adminrotated API key
systemdata export honored
EncryptionTLS · at rest
Data residencyregion-pinned
GDPR / CCPAaligned

SSO

and SAML 2.0 sign-in

Audit

logs & IP blocklisting

RBAC

role-based access & teams

GDPR

and CCPA aligned

/ 01The problem

Powerful AI raises the bar on security.

Agentic AI and broad channel access are exactly what make a communications platform useful — and exactly what a security team scrutinizes. The more an agent can do on its own, the more your controls have to hold.

Bolt-on security fails here. When SSO, permissions, and logging live in separate tools stitched around the product, there are gaps between them — and gaps are where reviews stall and incidents start.

FloatChat builds the controls into the platform by default, so enabling AI and broadcasting doesn't mean loosening your posture. You move fast without creating risk.

Security bolted on

  • Four vendors, four access models
  • Logs scattered or missing
  • No central deprovisioning
  • Reviews stall on the gaps

Security built in

  • One platform, one security model
  • Tamper-evident audit logs by default
  • SSO deprovisioning follows your IdP
  • Controls IT will approve
/ 02Key controls

The controls your security team asks for.

Strong defaults across access, visibility, and data handling — so enabling agentic AI never means loosening your posture.

SSO & SAML

Sign in through your identity provider — Okta, Azure AD, Google Workspace, or any SAML 2.0 IdP. Enforce MFA and central deprovisioning so access follows your directory, not a spreadsheet.

Role-based access

Scope every seat with granular, role-based permissions and organize people into teams. Give agents what they need to operate and analysts read-only visibility — nothing more.

Audit logs

A tamper-evident, timestamped record of who did what and when — sign-ins, role changes, exports, and configuration edits — exportable for your security reviews and investigations.

IP blocklisting

Restrict access to trusted networks with IP allow and block rules. Lock the workspace down to office ranges and your VPN, and shut out logins from anywhere else.

Encryption

Data is encrypted in transit with TLS and encrypted at rest. Sensitive credentials and API keys are stored securely and can be rotated and scoped whenever you need.

Data residency

Keep customer data where it belongs. Configurable data-residency controls help you meet regional requirements and internal data-handling policies.

GDPR & CCPA aligned

Data handling is aligned with GDPR and CCPA — lawful processing, data-subject access and deletion, and clear retention. SOC 2 is on the roadmap.

White-label & brand control

A white-label UI and customizable dashboards keep the experience on your brand, so security controls fit the way your team already works.

/ 03Data handling & compliance

Data handled the way regulators expect.

FloatChat's processing is aligned with the GDPR and the CCPA: lawful, minimized processing, support for data-subject access and deletion requests, and clear retention. You get one data-handling model across your AI, channels, and campaigns — not four different ones to reconcile.

Data is encrypted in transit and at rest, and configurable data-residency controls help you keep customer data in the region your policies require. SOC 2 is on our roadmap; the controls that underpin it — access, logging, and encryption — are already in place today.

Encryption in transit & at restData-subject access & deletionConfigurable data residencySOC 2 on the roadmap

GDPR & CCPA aligned

Lawful, minimized processing with a defensible basis and clear retention.

Subject requests

Honor access, export, and deletion requests without a fire drill.

Data residency

Pin customer data to the region your compliance program requires.

Encryption everywhere

TLS in transit, encryption at rest, and scoped, rotatable keys.

/ 04Access & authentication

Who gets in, what they can do, and a record of it all.

Identity from your IdP, permissions scoped to the role, network rules at the edge, and a tamper-evident log behind every action.

Authenticate

SSO & SAML

  • SAML 2.0 with Okta, Azure AD, Google
  • Enforce MFA at your IdP
  • Central, instant deprovisioning
Authorize

Roles & teams

  • Granular role-based permissions
  • Organize people into teams
  • Least-privilege by default
Restrict

IP blocklisting

  • Allow office ranges and VPN
  • Block everything else
  • Refused logins are recorded
Audit

Audit logs

  • Who did what, and when
  • Tamper-evident and timestamped
  • Exportable for reviews
Working in a regulated industry?
Get started

Bring agentic AI to your team with controls IT will approve.

Walk through SSO, audit logs, and data handling with our team on a live demo.

Security questions, answered

What IT and compliance teams ask before they approve FloatChat.

Yes. FloatChat supports single sign-on over SAML 2.0, so your team signs in through your existing identity provider — Okta, Azure AD, Google Workspace, or any SAML-compatible IdP. You can enforce MFA at the IdP and deprovision access centrally, so when someone leaves your directory they lose access here too.

Enterprise controls, on by defaultSSO · audit · RBAC

Adopt agentic AI with the controls IT will approve.

SSO and SAML, audit logs, IP blocklisting, role-based access, and GDPR/CCPA-aligned data handling — built into FloatChat, ready for your security review.