Security
Last update: August 2026. Applies to all 360 Technologies USA LLC platforms and services
Your data is our priority.
360 Technologies USA LLC implements advanced security controls comparable to those used by leading e-commerce platforms, financial institutions, and regulated service providers. Our products (Live 360, ClickSign 360, Flash Team 360, Hi360x) are built on an architecture designed to protect the confidentiality, integrity, and availability of your information.
NEW (August 2026): With the launch of 360x AI, we have implemented additional security measures and documented our complete data protection architecture in our new “Data Protection & Security Addendum.”
360 Technologies USA LLC implements advanced security controls comparable to those used by leading e‑commerce platforms, financial institutions, and regulated service providers. Our products (Live 360, ClickSign 360, Flash Team 360, Hi360x) are built on an architecture designed to protect the confidentiality, integrity, and availability of your information.
Encryption and Data Protection
- SSL/TLS encryption for all data transmitted between your device and our servers.
- AES‑256 encryption for data stored in the cloud.
- Secure authentication with strong passwords and two‑factor authentication (2FA) via SMS or compatible apps.
- Industry‑standard key management to ensure encrypted data remains inaccessible without proper authorization.
Cloud encryption ensures that your information is unreadable without the correct keys—even if data is lost, stolen, or accessed improperly. These measures support compliance with modern data privacy and protection standards.
Certification Disclosure
360 Technologies USA LLC operates on Amazon Web Services (AWS), which maintains SOC 2 Type II certification for its infrastructure and physical security controls.
360 Technologies USA itself is not SOC 2 certified, and no statement in this Security Policy shall be interpreted as representing or implying that 360 Technologies USA holds a SOC 2 certification.
We implement internal controls aligned with SOC 2 Trust Services Criteria; however, these controls do not constitute a formal SOC 2 audit or certification.
360x AI SECURITY (NEW – August 2026)
What is 360x AI?
360x AI is an intelligent assistant integrated directly into Live 360, available in two pricing tiers (Free and Pro). It processes insurance policy data to provide analysis, communications, and insights.
360x AI Data Protection
CRITICAL: 360x AI implements enterprise-grade security measures:
- Encryption: All 360x AI queries and responses are encrypted in transit (TLS 1.2+) and stored data is encrypted at rest (AES-256)
- Access Control: Role-based access control (RBAC) ensures only authorized users can access their data
- Audit Trail: Every 360x AI interaction is logged for compliance and auditing purposes (6-year HIPAA retention; 10-year CMS retention for applicable data).Data Isolation: Each customer’s data is logically isolated with no cross-tenant data sharing
- Retention & Deletion: 360x AI conversation history is stored in your Live 360 account and can be deleted anytime
- AI Model Security: Your data is never used for model training; processing occurs in real-time, in-memory
- No External Sharing: Your data is never transmitted to external AI providers
- Breach Notification: We will notify you within 24-72 hours of any confirmed breach involving 360x AI data
360x AI Compliance
HIPAA & CMS Compliance
When customers process Protected Health Information (PHI), 360 Technologies USA LLC acts as a Business Associate under HIPAA (45 CFR 160/164) and CMS beneficiary data handling requirements.
A Business Associate Agreement (BAA) with OpenAI governs authorized AI processing.
PHI may only be processed within Live360 and 360x AI.
ClickSign 360 and Hi360x are not authorized to process PHI.
360x AI is designed to meet or exceed:
- HIPAA security standards (though customers determine HIPAA applicability)
- GDPR data protection requirements
- CCPA/CPRA compliance obligations
- SOC 2 Type II standards (in progress)
For detailed technical specifications: See our “Data Protection & Security Addendum” (available upon request under NDA).
HI360X AI SECURITY
Hi360x data is protected with the same enterprise-grade security as our other services:
- Encryption: All Hi360x data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Access Control: Role-based access control (RBAC) with audit logging for all AI interactions
- Data Isolation: Hi360x customer data is logically isolated per tenant
- Retention & Deletion: Automated deletion of Hi360x data after 12 months or upon customer request
- AI Model Training: Hi360x does not use customer data for model training, fine‑tuning, or model improvement.
- Audit Trail: Comprehensive logging of all Hi360x access and interactions
- Breach Notification: We will notify you within 72 hours of any confirmed breach involving Hi360x data
- Regular Audits: Our AI systems undergo quarterly security reviews and penetration testing
External AI Integrations Prohibited
360 Technologies USA LLC does not permit, enable, or support transmission of personal information or PHI to external AI assistants, external AI models, or third‑party agent platforms.
All AI operations occur exclusively within the 360 Technologies USA AI Gateway or OpenAI under a Business Associate Agreement (BAA).
External AI integrations, including MCP or similar protocols, are not authorized and must not be used with any 360 Technologies product.
Hi360x data is protected with the same enterprise-grade security as our other services:
– Encryption: All Hi360x data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
– Access Control: Role-based access control (RBAC) with audit logging for all AI interactions
– Data Isolation: Hi360x customer data is logically isolated per tenant
– Retention & Deletion: Automated deletion of Hi360x data after 12 months or upon customer request
– AI Model Security: No customer data is used for model training or model improvement.
– Breach Notification: We will notify you within 72 hours of any confirmed breach involving Hi360x data
– Regular Audits: Our AI systems undergo quarterly security reviews and penetration testing
Secure Cloud Infrastructure
We partner with top‑tier cloud providers that maintain internationally recognized security certifications, including:
- AWS maintains SOC 1, SOC 2, and SOC 3 certifications for its infrastructure. 360 Technologies USA LLC is not SOC 2 certified and does not claim SOC 2 compliance.
- ISO 27001
- HIPAA/HITECH
- PCI DSS (when applicable)
Our infrastructure includes:
Certification Disclosure
360 Technologies USA LLC operates on Amazon Web Services (AWS), which maintains SOC 2 Type II certification for its infrastructure and physical security controls.
360 Technologies USA itself is not SOC 2 certified, and no statement in this Security Policy shall be interpreted as representing or implying that 360 Technologies USA holds a SOC 2 certification.
We implement internal controls aligned with SOC 2 Trust Services Criteria; however, these controls do not constitute a formal SOC 2 audit or certification.
- Network segmentation
- Managed firewalls
- Intrusion detection and prevention systems (IDS/IPS)
- Role‑based access controls (RBAC)
- Continuous auditing and activity logging
Backup and Reliability
To ensure service continuity and data durability:
- Multiple backups are performed throughout the day.
- Data is replicated across redundant geographic zones.
- Disaster Recovery (DRP) and Business Continuity (BCP) plans are in place.
- Systems operate with fault tolerance and load balancing.
This guarantees that your information remains available even during unexpected events or hardware failures.
Privacy and Data Ownership
Your information belongs exclusively to you. 360 Technologies USA LLC does not sell, rent, or trade user data under any circumstances.
We apply strict controls to protect data confidentiality and integrity, including:
- Automated integrity checks
- Internal quality assurance processes
- Role‑restricted access
- Monitoring for suspicious or unauthorized activity
Users may request data exports in Excel/CSV formats at any time by contacting: info@360techusa.com
PHI Processing Authorization
The following products are authorized to process PHI under a valid BAA:• Live360
* 360x AI
The following products are not authorized to process PHI:• ClickSign 360
* Hi360x
Users must not upload, transmit, or store PHI in non‑PHI products.
24/7 Monitoring and Supervision
Our systems are monitored in real time 24x7x365. Monitoring includes:
- Network and server health
- Application performance
- Security anomalies
- Unauthorized access attempts
- Unusual behavior that may affect user experience
Any incident is addressed immediately by our security and operations teams.
Incident Response and Breach Notification
Although we employ advanced security measures, no internet‑connected system can be guaranteed completely secure.
In the unlikely event of a data breach:
-Our Incident Response Protocol will be activated.
-Affected users will be notified promptly.
-Mitigation and corrective actions will be implemented.
-The event will be documented according to applicable compliance standards.
Regulatory Incident Response Requirements
Security incidents involving PHI will be handled according to HIPAA breach notification rules (45 CFR 164.400–414).
Incidents involving CMS beneficiary data will follow CMS incident reporting requirements, including timely notification and documentation.
