Security

Your security is our top priority. Learn about the measures we take to protect your data.

Signed & Scanned Images | Tenant Isolation (RLS) | Continuous Monitoring

Security Features

Comprehensive security at every layer

Encryption

All traffic is encrypted in transit, and sensitive call data is encrypted at rest at the database layer.

  • TLS for all API and web traffic (Cloudflare edge + Traefik)
  • Call PII (recordings, transcripts) encrypted at rest via pgcrypto (AES)
  • Secrets held in Infisical — never committed to source
  • Provider API calls are HTTPS-only

Authentication

Asymmetric, centrally-issued tokens and scoped API keys protect your account and API access.

  • RS256 (asymmetric) JWTs, verified against a JWKS endpoint
  • Per-organization API keys with default-deny scope allowlisting
  • Tenant isolation enforced at the database via row-level security
  • Session management and timeout controls

Access Control

Fine-grained access control to manage permissions across your organization.

  • Role-based access control (RBAC)
  • Scoped API keys — default-deny, explicit scope allowlist
  • Audit logging of security-relevant actions
  • Team member permission management

Infrastructure

A dedicated, single-region deployment with a hardened supply chain.

  • Container images signed with Cosign (keyless/OIDC) on every build
  • Trivy image scanning, SAST, and secret scanning enforced in CI
  • DDoS mitigation and WAF at the Cloudflare edge
  • Automated dependency updates and security patching

Compliance Posture

What we can substantiate — and what we can't

Not attested

SOC 2 Type II

Type 1 control objectives (CC6.1, CC6.6, CC6.7, CC7.2, CC7.3, A1.2, C1.1) are implemented at the API substrate and verified in our internal audit. An independent Type II attestation has not been performed.

Controls in place

GDPR / CCPA

Consent capture, erasure-by-consent, and PII-safe handling are implemented in the data path. DPA templates are available on request.

Addressed

OWASP Top 10

A01–A10 reviewed and closed at the API substrate level (auth, injection, access control, misconfiguration) in our internal security audit.

Not offered

HIPAA

We do not offer a BAA and do not represent the platform as HIPAA-compliant. Please do not send PHI through the platform.

Security Practices

Proactive measures to keep your data safe

Internal Security Audits

Each service goes through a documented, per-vertical security audit before it ships. We have not yet engaged a third-party penetration tester.

Vulnerability Management

Trivy container scanning, SAST, and secret scanning run automatically in CI on every build, with automated dependency updates.

Responsible Disclosure

Report a vulnerability to [email protected] and we will investigate. We do not currently run a paid bug bounty.

Monitoring & Incident Response

Continuous automated uptime, error, and log monitoring (Uptime Kuma, GlitchTip, Loki/Prometheus/Grafana) alerting the on-call maintainer.

Data Handling & Retention

Audio Data

Audio data processed through our API is not stored by default. Enterprise customers can optionally enable storage for quality assurance purposes with configurable retention periods.

API Logs

API request logs are retained for 30 days to support debugging and analytics. Logs can be configured or disabled based on your compliance requirements.

Data Deletion

You can request deletion of your data at any time. We comply with data deletion requests within 30 days as required by applicable regulations.

Report a Security Issue

We take security issues seriously. If you discover a vulnerability, please report it to our security team. We appreciate your help in keeping our platform secure.