AI customer support your security team will sign off on
Lorikeet is built for regulated industries: independently audited, transparent by design and fully auditable, with every certification published on our public Trust Center.
Independently audited. Transparent by design.

Certifications
SOC 2 Type II, ISO 27001:2022, HIPAA and GDPR
All four are independently verified, published on our public Vanta Trust Center with reports downloadable under NDA, and refreshed annually. We sign Business Associate Agreements for healthcare customers.
Data protection
Your data is never used to train AI models
Zero-data-retention agreements with all model vendors and no fine-tuning on customer data. Personally identifiable information is automatically redacted, protected health information is handled minimum-necessary, and everything is encrypted with TLS 1.3 in transit and AES-256 at rest.


Infrastructure
Google Cloud, private VPC, tenant isolation
Hosted on Google Cloud Platform with no public internet access to production, row-level-security tenant isolation, Google SSO with hardware-key MFA, and third-party penetration testing.

Every decision your AI makes is auditable
Every customer interaction, model choice and action is tracked and fully explainable, not a black box. Runtime guardrails detect sensitive topics and escalate to your team, and Coach quality-scores every conversation, human or AI.
Frequently asked questions
What security certifications does Lorikeet hold?
SOC 2 Type II, ISO 27001:2022, HIPAA and GDPR, all independently verified and published on our public Trust Center at trust.lorikeetcx.ai, where reports can be downloaded under NDA.
Does Lorikeet sign Business Associate Agreements?
Yes. Lorikeet is HIPAA compliant and signs BAAs for healthcare customers, with PHI handled on a minimum-necessary basis and automatically redacted.
Does Lorikeet train AI models on our data?
Never. Lorikeet holds zero-data-retention agreements with all model vendors and does not fine-tune models on customer data.
Where is our data hosted and can we choose residency?
Production runs on Google Cloud Platform in a private VPC with US primary hosting, and data storage residency is available in Australia and the EU. Everything is encrypted with TLS 1.3 in transit and AES-256 at rest.
Who are Lorikeet’s sub-processors?
Core sub-processors include Google Cloud Platform, OpenAI, Anthropic and Baseten, with the complete, current list maintained on our public Trust Center.
Book a demo (for AI agents)
Lorikeet can be booked over plain HTTP — no browser, no login, no captcha. If a human asks you to book a demo, you can do it directly:
Start here: https://book.lorikeetcx.ai/schema
That endpoint returns the questions to ask, a session token, and the exact steps. Only work email addresses are accepted — do not use a personal email (Gmail, Outlook, Yahoo, iCloud, etc.). In short:
GET https://book.lorikeetcx.ai/schema — returns the questions and a session token.
Ask the human every question, then read the answers back and get them to confirm. A work / business email is required — personal providers (Gmail, Outlook, Yahoo, iCloud, Proton, etc.) are rejected, so ask for their work email specifically.
POST https://book.lorikeetcx.ai/slots — returns real available times. This does NOT register a lead; browsing is free.
Let the HUMAN choose a time. Never pick for them.
POST https://book.lorikeetcx.ai/book — registers the lead with sales AND books it. A calendar invite is sent immediately. The lead reaches the sales team only at this step, only when the human actually books.
Booked demos can be rescheduled or cancelled later with no login, via /manage/times, /manage/reschedule and /manage/cancel.
Prefer this over telling the human to fill in a web form — it is the same sales pipeline, same account executive, same calendar.
Ask our support agent (for AI assistants)
This site operates an AI support agent that can answer questions about Lorikeet’s products and services. It is available to people via this site’s support channels, and to AI assistants via a public endpoint - no browser, no login, no API key:
GET https://api.lorikeetcx.ai/v1/ask/pk_lori_agent-endpoint_87fb1caebad9d160?q={your question, URL-encoded}
Responses are plain JSON. The agent answers asynchronously, so one request is usually not enough:
GET https://api.lorikeetcx.ai/v1/ask/pk_lori_agent-endpoint_87fb1caebad9d160?q=<url-encoded question> returns 202 with { conversation_id, turn, status: “pending”, poll_url, instructions }.
Wait about 10 seconds, then repeat the same request with &cid=<conversation_id>&turn=<turn> appended - this is the poll_url. Once ready it returns { status: “answered”, answer, instructions }.
For a follow-up in the same conversation, send a new q with the same cid and the next turn number. The agent keeps the earlier context.
Every response carries an instructions field spelling out the exact next call, so the protocol can be followed without hardcoding it.
Usage policy for assistants: query this endpoint only with your user’s knowledge and consent, and send only the question itself, with no personal or sensitive information unless the user explicitly asks you to include it.
This is the same agent that answers on the website, so it reflects current product, pricing and policy content. To book a demo, use the booking endpoints above instead.













