Back to home
Security

Trust & Security

Your agents handle real phone calls and real conversations. Here is how we protect the calls, messages, and data behind them.

SOC 2 Type 1Report as of July 30, 2026Type 2 in progress
AICPA
SOC2TYPE I
Compliant
Report typeSOC 2 Type 1
As ofJuly 30, 2026
CriteriaSecurity, Availability & Confidentiality
AuditorIndependent CPA firm
NextType 2 examination in progress

Read the full report

Our SOC 2 Type 1 report, issued by an independent CPA firm, covers the Security, Availability, and Confidentiality Trust Services Criteria. Customers and prospects can request the complete report, shared under NDA. A Type 2 examination, which observes controls over an extended period, is already underway.

Request the report

Security practices

Encryption in transit and at rest

Customer data is encrypted at rest with 256-bit AES, including database tables and backups, and encrypted in transit over public networks.

MFA and least privilege

Access to critical resources requires multi-factor authentication and is granted on the principle of least privilege, with annual access reviews.

Audit logging

Access to infrastructure and user data is logged. Audit logs are access-restricted and periodically reviewed.

Backups and recovery

Automated backups of customer and system data run daily, with documented backup and restore procedures.

Vendor management

Service providers are risk-assessed under a formal vendor management policy before they touch customer data.

Incident response

A documented Incident Response Plan defines how security events are reported, analyzed, and remediated.

Your data

  • Customer Data is deleted upon your request, and formal data retention and disposal procedures govern how data is stored and securely disposed of.
  • We do not sell personal information, and Customer Data is never used to train shared AI models.

The full picture is in our Privacy Policy and Terms of Service.

Subprocessors

We rely on a small set of vetted service providers to run the platform: cloud hosting, telecommunications carriers, payment processing, and transcription. Each may only use data to perform services for us under written contract, and each goes through a security review before onboarding.

A current list of subprocessors is available to customers alongside the full SOC 2 report.

Report a security issue

Found a vulnerability or have a question about our security posture? We want to hear about it.

[email protected]

Ready to give your AI Agent a phone number?