Last updated 2026-07-25
How we protect your calls.
Phone calls carry some of the most sensitive things your customers will ever tell you. This page sets out what we actually do about that — and what we do not yet claim.
Encryption
- In transit. Every connection to the console and the API is over TLS, with HTTP strictly redirected to HTTPS. Call media is encrypted between the caller and our media servers.
- At rest. Your account data, agent profiles and call transcripts are stored encrypted at rest by our database and cloud providers.
Tenant isolation
Every agent belongs to exactly one account, and every request that reads or writes agent data is scoped to the account that owns it. One customer's agents, call history and uploaded documents are never served to another. Call sessions are dispatched per call with the identity of the business baked into the dispatch, so a call cannot be answered with another business's profile.
Authentication and access
- Every request that reads or changes your data must carry a valid signed session token, verified on the server against our identity provider on each request. The only endpoints reachable without one are the public demo gate and this site's contact form, which are write-only and separately rate limited.
- The public showcase agents are separately gated by SMS one-time passcode with a strict per-number usage limit, so they cannot be used as an open calling service.
- Access to production systems is limited to the engineers who need it to operate the service.
Where call media runs
The real-time media stack that carries call audio runs on infrastructure we operate, rather than being handed to a third-party calling platform. Speech-to-text, text-to-speech and the language model are provided by specialist vendors — which ones depends on how your agent is configured, and if you supply your own model API keys, those calls run on your account with that provider. The current list is in our privacy policy.
Auditability
Every call is recorded in your call history as a full transcript with per-turn, per-stage response timings and call metadata. You can read exactly what was said on any call, which agent handled it and how long each stage took. This is what lets you verify agent behaviour rather than take our word for it.
Guardrails on what an agent can say
Agents answer strictly from the profile built out of your own documents, under a locked behaviour scaffold that cannot be edited away: no invented prices, no promises your policies do not support, and an honest handover when a question falls outside what the agent knows. This is a safety property as much as a quality one.
What we do not claim
We would rather be straight with you than imply more than we have. We do not currently hold SOC 2, ISO 27001 or any equivalent third-party certification, and we do not claim to. If your procurement process requires one, tell us — it is useful for us to know what is blocking.
Reporting a vulnerability
If you think you have found a security issue, please tell us through the contact form rather than disclosing it publicly, and give us a reasonable window to fix it. Include enough detail to reproduce it. We will acknowledge your report, keep you updated, and we will not pursue action against researchers who act in good faith, avoid privacy violations and do not degrade the service.
For questions about what data we hold and for how long, see the privacy policy, or get in touch.