Security

Built like we're touching your customer data. Because we are.

You're wiring an outside system into your CRM and phone lines. Here is exactly how that access works, what we do with your data, and what we refuse to do with it.

The architecture.

How your data is held.

01

Encryption everywhere

TLS 1.2+ (1.3 preferred) for every byte in transit; encryption at rest for recordings, transcripts, and records.

02

Per-tenant isolation

Your data lives in its own logical boundary. No shared indexes, no cross-tenant queries, no bleed.

03

Least-privilege access

Integrations run on scoped service accounts with the minimum permissions the workflow needs — created with you, revocable by you in one click.

04

MFA & access logging

Internal access to production systems requires MFA and is logged. Humans review your calls only for QA and tuning.

05

No shared-model training

Your customer data never trains models shared with other customers. Improvements to your agent stay yours.

06

No data resale. Ever.

We are paid by subscription, not by your data. We do not sell, rent, or broker customer information — contractually.

Commitments in writing.

These live in the Master Services Agreement and Data Processing Addendum, not just on this page.

Who owns the data?
You do. Call recordings, transcripts, and customer records processed on your behalf are your data. On termination you get a 30-day export window, then deletion on a defined schedule.
What about breach notification?
We notify you without undue delay and within 72 hours of confirming a breach affecting your data, with the facts we have and the remediation under way.
Which subprocessors touch the data?
Categories: cloud hosting, telephony carriage, speech-to-text, text-to-speech, language models, and payments. The current list is available on request and changes are notified in advance.
Call recording consent?
Recording and disclosure rules vary by state. The agent's greeting and disclosure behavior is configured to your jurisdictions during onboarding, and the responsibility split is spelled out in the MSA.
HIPAA?
Standard plans are not a HIPAA environment and shouldn't carry PHI. HIPAA workflows with signed BAAs are available on Enterprise — raise it on the kickoff call.
SOC 2?
A SOC 2 Type II audit is in progress. Ask and we'll share current status and timeline honestly rather than a badge that overstates it.
SECURITY QUESTIONS?
Priced to your call volume
Flat monthly rate · month-to-month · quoted on your kickoff call
  • Full MSA & DPA at /terms
  • Subprocessor list on request
  • Security review calls welcome
  • Enterprise: custom DPAs & BAAs
Book a strategy call