Compliance & Security
Enterprise-grade security and compliance for your voice AI applications
Compliance Posture
An honest account of where we stand. We list only what we can substantiate — if an attestation is not shown as held here, we do not hold it.
SOC 2 Type II
Not attestedType 1 control objectives are implemented and internally audited. No independent Type II attestation has been performed.
GDPR / CCPA
Controls in placeConsent capture, erasure-by-consent, and PII-safe handling are implemented in the data path. DPA templates on request.
Supply chain
Enforced in CIContainer images are signed (Cosign, keyless/OIDC) and scanned (Trivy) on every build, alongside SAST and secret scanning.
HIPAA
Not offeredWe do not offer a BAA and do not represent the platform as HIPAA-compliant. Please do not send PHI through the platform.
Security Infrastructure
Encryption in Transit
All public traffic is served over TLS. Call PII (recordings, transcripts) is additionally encrypted at rest at the database layer via pgcrypto (AES).
Data Residency
Single-region today: the platform runs on a dedicated EU VPS. Regional/multi-region deployment is on the roadmap and is not yet available.
Access Controls
Per-organization tenant isolation enforced by Postgres row-level security, RS256 (JWKS-verified) auth, scoped API keys, and audit logging.
Network Security
Cloudflare edge provides TLS termination, DDoS mitigation, and WAF in front of the platform.
Enterprise Compliance Questions?
We're happy to walk through our controls, complete a security questionnaire, or discuss a DPA. We can share our internal control documentation — we cannot share a SOC 2 report, because no independent attestation has been performed yet.
Contact Security Team