For your security team

Security and data

This page covers how we keep your data separate, who handles a call, what we store, and how deletion works.

Send us your security questionnaire.

Talk to us

Each client's data is kept separate

Every company has its own workspace. No other company on the platform can see or reach it.

Full detail

Each workspace holds that company's own records, call history, documents, team and analytics. Nothing is pooled, mixed or combined across companies: not for reporting, not for tuning, not for anything. Your own administrator reviews access to your workspace before an account is opened.

Who handles a call

Besides us, three outside parties handle a call: the voice platform, the phone carrier and the AI model provider. Open each to see what it holds and for how long.

  1. Your customer
  2. Phone carrier
  3. Voice platform
  4. AI model provider
  5. Us
Us

Holds:your records as you connect them, call transcripts and summaries, our copy of the recording, and the audit record of who looked at what.

For how long:as long as your workspace holds the call. One retention period for the whole platform is planned but not yet switched on, so nothing is deleted automatically today. Deletion is by request, and our copy is the one we can delete when you ask.

The voice platform

The company that runs the call and the AI voice agent's language model.

Holds:the call audio, its own transcript, and its own record of the call for billing and analytics.

For how long:it keeps its copy of the audio for around two weeks, then deletes it. Its call record follows its own schedule, not ours.

The phone carrier

The network that connects your customer and your representative.

Holds:the phone connection, and its own recording of the part of the call your representative is on.

For how long:its own schedule, as a phone carrier.

The AI model provider

The company whose language model writes the spoken reply.

Holds:the words of the call as they are spoken, including figures about to be read out. It has no access to your records and never holds your workspace.

For how long:this depends on the contract in force. We answer it with that contract in front of us.

Where the AI model runs

On phone calls, the language model runs at the voice platform. There is no private or on-premise model on phone calls. For the chat assistant and the call summary, you choose the model provider. That includes a model that runs on our own servers and sends nothing out.

Training

We make no claim about whether these companies train on what passes through them. That depends on the contracts in force, and we answer it with those contracts in front of us.

What we ask callers for, and what we keep

Card numbers and security codes are masked before any transcript is saved. What a caller must give to verify identity is agreed and set up with you.

Full detail

Every customer service team follows its own rules, so the verification questions are agreed and set up with you. Whatever is asked, card numbers, security codes and similar identifiers are masked before a transcript is written down.

One limit: a recording is audio. If a caller says something we did not ask for, it is in the audio of that call, and transcript masking does not reach it. That is why recording is configurable per company, and why statutory recording is a deliberate choice, not a default.

Recording and disclosure

Recording and disclosure are configurable per company. Each call leaves a recording and a transcript, plus a summary when the call is handed to a representative. The recording is the official record.

Full detail

Settings include a statutory mode in which every call is recorded and the caller is told so at the start, with no implied opt-out we do not have the authority to offer. A representative is never told a call is recorded unless it actually is.

The three records are not interchangeable: the recording is the authoritative artifact, the transcript is derived with any gaps marked, and the summary is a convenience that is never evidence.

Deleting data

When you ask, we delete a call's recording from our storage and log that we did it. Copies held by the outside parties expire on their own schedule.

Full detail

When you ask us to remove a call's media, it is removed from our storage and the removal is written into the audit record. Removing a call's whole record from your workspace is also a request to us, which we carry out. Neither is a button you press yet (see On our roadmap). We do not control how long the outside parties in topic 2 keep their copies.

Who can see what

Downloads, exports and deletions are logged: who did what, when, and to which record. Team members with the right access can read along with a live call.

Full detail

Read-along happens inside your own workspace. There is no listening in. Your administrator reviews access to a workspace before an account is opened.

On our roadmap

  • A button to delete a call's record from your workspace. Today you ask us, and we do it.
  • Automatic deletion of older call data. One retention period for the whole platform is planned; it is not switched on yet.

Questions from your security team?

Send us your questionnaire. We answer it based on how the product works today.

Access to a workspace is reviewed before an account is opened.