AI Dispatch
The wirewireSep 23, 2026

Customer-support agent Gladly lists SOC 2 Type II, PCI DSS, HIPAA, GDPR and CCPA compliance, commits to 99.9% uptime; discloses no insurance or liability terms

The AI customer-service platform's security page details audit logging and human-review controls but says nothing about indemnification or coverage limits.

Gladly, an AI-driven customer-support platform, states on its security page that it "meets security requirements for InfoSec teams, including SOC 2 Type II, PCI DSS, HIPAA, GDPR, CCPA, annual penetration testing, and data encryption at rest and in transit," according to the page, retrieved Sept. 20. The list spans a security-controls audit (SOC 2 Type II), the payment-card-data standard (PCI DSS), the U.S. healthcare-privacy law (HIPAA) and the EU and California privacy regimes (GDPR, CCPA).

The company also commits to "99.9% uptime with redundant architecture and auto-failover." On oversight of AI-generated customer replies, Gladly says "every AI response goes through automated checks, policy enforcement, human audits, and traceable logs to ensure accuracy and compliance" — a human-review layer sitting on top of the automated system rather than replacing it.

On the audit-trail dimension specifically, the company says it gives customers "versioning, audit logs, model routing transparency, telemetry, and rollback controls for full observability" across their deployment. The page does not say whether those logs are cryptographically tamper-evident or only access-controlled.

The same security page — the most detailed public disclosure Gladly makes about its controls — does not mention insurance, indemnification or a contractual liability cap. Of the five trust-gap dimensions AI Dispatch tracks, Gladly's disclosure covers compliance and audit trail in detail and addresses a form of runtime governance through its human-audit layer on AI outputs. It says nothing about outcome settlement or insurance/indemnity — the two dimensions that determine who bears the cost if an AI-generated response causes a customer harm.

Entries in this piece 1

Published index entries backed by the same source documents this piece cites.

Sources 4

  1. Gladly meets security requirements for InfoSec teams, including SOC 2 Type II, PCI DSS, HIPAA, GDPR, CCPA, annual penetration testing, and data encryption at rest and in transit.
    gladly.ai · checked Sep 20, 2026
  2. 99.9% uptime with redundant architecture and auto-failover
    gladly.ai · checked Sep 20, 2026
  3. Every AI response goes through automated checks, policy enforcement, human audits, and traceable logs to ensure accuracy and compliance.
    gladly.ai · checked Sep 20, 2026
  4. Gladly gives you versioning, audit logs, model routing transparency, telemetry, and rollback controls for full observability across your environment.
    gladly.ai · checked Sep 20, 2026