Security
Your security is our top priority. Learn about the measures we take to protect your data.
Signed & Scanned Images | Tenant Isolation (RLS) | Continuous Monitoring
Security Features
Comprehensive security at every layer
Encryption
All traffic is encrypted in transit, and sensitive call data is encrypted at rest at the database layer.
- TLS for all API and web traffic (Cloudflare edge + Traefik)
- Call PII (recordings, transcripts) encrypted at rest via pgcrypto (AES)
- Secrets held in Infisical — never committed to source
- Provider API calls are HTTPS-only
Authentication
Asymmetric, centrally-issued tokens and scoped API keys protect your account and API access.
- RS256 (asymmetric) JWTs, verified against a JWKS endpoint
- Per-organization API keys with default-deny scope allowlisting
- Tenant isolation enforced at the database via row-level security
- Session management and timeout controls
Access Control
Fine-grained access control to manage permissions across your organization.
- Role-based access control (RBAC)
- Scoped API keys — default-deny, explicit scope allowlist
- Audit logging of security-relevant actions
- Team member permission management
Infrastructure
A dedicated, single-region deployment with a hardened supply chain.
- Container images signed with Cosign (keyless/OIDC) on every build
- Trivy image scanning, SAST, and secret scanning enforced in CI
- DDoS mitigation and WAF at the Cloudflare edge
- Automated dependency updates and security patching
Compliance Posture
What we can substantiate — and what we can't
SOC 2 Type II
Type 1 control objectives (CC6.1, CC6.6, CC6.7, CC7.2, CC7.3, A1.2, C1.1) are implemented at the API substrate and verified in our internal audit. An independent Type II attestation has not been performed.
GDPR / CCPA
Consent capture, erasure-by-consent, and PII-safe handling are implemented in the data path. DPA templates are available on request.
OWASP Top 10
A01–A10 reviewed and closed at the API substrate level (auth, injection, access control, misconfiguration) in our internal security audit.
HIPAA
We do not offer a BAA and do not represent the platform as HIPAA-compliant. Please do not send PHI through the platform.
Security Practices
Proactive measures to keep your data safe
Internal Security Audits
Each service goes through a documented, per-vertical security audit before it ships. We have not yet engaged a third-party penetration tester.
Vulnerability Management
Trivy container scanning, SAST, and secret scanning run automatically in CI on every build, with automated dependency updates.
Responsible Disclosure
Report a vulnerability to [email protected] and we will investigate. We do not currently run a paid bug bounty.
Monitoring & Incident Response
Continuous automated uptime, error, and log monitoring (Uptime Kuma, GlitchTip, Loki/Prometheus/Grafana) alerting the on-call maintainer.
Data Handling & Retention
Audio Data
Audio data processed through our API is not stored by default. Enterprise customers can optionally enable storage for quality assurance purposes with configurable retention periods.
API Logs
API request logs are retained for 30 days to support debugging and analytics. Logs can be configured or disabled based on your compliance requirements.
Data Deletion
You can request deletion of your data at any time. We comply with data deletion requests within 30 days as required by applicable regulations.
Report a Security Issue
We take security issues seriously. If you discover a vulnerability, please report it to our security team. We appreciate your help in keeping our platform secure.