How we handle your data.
An honest overview of our security posture, written for the person who has to sign off on the vendor review. Where something is in progress rather than complete, it says so.
Security controls
Encryption
Data encrypted in transit with TLS and at rest using industry-standard algorithms. Secrets and credentials are stored in a managed secrets service, never in configuration.
Access control
Role-based access within the platform, least-privilege internal access, and audit logging on administrative actions and transcript access.
Data residency
Choose the region your data is stored and processed in. Cross-region processing is not performed without explicit agreement.
PII handling
Configurable redaction on ingest, restricted fields an agent may never repeat, and retention windows you define per data category.
Subprocessors
A current list of subprocessors, including model providers, is available on request and covered in the DPA. We notify customers of material changes.
Model data use
Customer data is not used to train foundation models. Where model providers are used, we contract for zero-retention or bounded-retention handling.
Certifications and audits
We do not currently hold SOC 2 or ISO 27001 certification. We are an early-stage company and we are not going to imply an attestation we have not earned — you will find out during the vendor review anyway, and it is a bad way to start a relationship.
What we do have is the underlying practice: the controls described on this page are implemented, and we are happy to walk your security team through them in detail, answer a questionnaire, or take part in an architecture review. Formal certification is on our roadmap; if your procurement process has a hard requirement for it today, tell us early and we will be straight with you about whether the timing works.
Compliance posture
Our data processing terms are designed to support customers with obligations under India's Digital Personal Data Protection Act, 2023. For customers with European or United Kingdom exposure, we contract on terms intended to support GDPR and UK GDPR processor obligations, including standard contractual clauses where transfers require them.
A Data Processing Agreement is available for signature as part of contracting. Have counsel confirm this list matches the markets you actually sell into before it is relied on in a contract.
Where our customers deploy agents that speak to consumers by phone, additional sector and telecoms rules may apply in their market. We build the controls — disclosure, consent capture, do-not-call enforcement, calling windows — but the customer remains the party responsible for compliance in their jurisdiction.
Reporting a vulnerability
If you believe you have found a security issue, email [email protected] with "Security" in the subject line and enough detail to reproduce it. We will acknowledge within two working days and keep you updated until it is resolved. We will not pursue legal action against researchers who report in good faith, avoid privacy violations and service degradation, and give us reasonable time to fix the issue before disclosure.
Business continuity
Automated backups with a defined recovery point and recovery time objective, documented in the service agreement. Restoration procedures are tested on a regular schedule.
Asking us more
Security questionnaires, architecture reviews, and penetration test summaries are handled as part of the sales process. Get in touch and we will route you to someone who can answer technically rather than send a brochure.
Send us your security questionnaire.
We would rather do the vendor review properly and early than discover a blocker in month three.