Security

Everything is encrypted. Built in from day one.

0:00 / 0:00

What stands behind your data

  • AES-256 encryption — In transit · at rest

    AES-256 encryption

    In transit · at rest

  • Unique key per account — Your key opens only your data

    Unique key per account

    Your key opens only your data

  • Verified access — Identity confirmed every time

    Verified access

    Identity confirmed every time

  • Data isolation — Enforced by the database

    Data isolation

    Enforced by the database

  • SOC 2 Type II — Independently audited

    SOC 2 Type II

    Independently audited

  • ISO 27001 — Certified standard

    ISO 27001

    Certified standard

How your data is protected

Five layers. Each one verifiable.

01

Encryption

Everything is encrypted.

Every file, call recording, document, and transcript — while it moves and while it sits.

Encrypted in transit

From your phone or computer to our servers, your data travels encrypted. Nothing crosses the wire in the clear.

Encrypted at rest

It stays encrypted in storage. It is only decrypted when you request access — and we’ve verified it’s actually you.

AES-256

The same standard widely used by banks, government agencies, and major tech companies.

A unique key for every account

Even someone who somehow reached the storage itself would see unreadable data. Without your key there’s no access — and your key can’t unlock anyone else’s information.

02

Access control

Identity is verified. Every time.

Access isn’t granted once and remembered. It’s checked on every request.

Verified on every access

Each time data is accessed, we verify who is asking before anything is decrypted.

Passwords are never stored readable

Your password lives only as a one-way mathematical hash. Even our own team can’t simply look it up.

03

Isolation

Your data is isolated from every other customer’s.

Separation isn’t left to the application alone.

Isolated by account

Your information is kept apart from every other customer’s, by design — not by policy.

Enforced by the database itself

The database enforces which account can access which information — an independent layer beneath the application.

04

Sharing

No public links. Ever.

Sharing a document or a call recording never means exposing it.

Secure, time-limited links

A shared document link is tied to that one document and expires. Once it expires, it no longer works.

Call recordings, the same way

Nothing floats around publicly. You request access, we verify the request, and then you can view it.

05

Independent verification

Don’t take our word for it.

The infrastructure behind it is reviewed by independent auditors against recognized standards.

SOC 2 Type II

Independent auditors review how data is protected — over a sustained period, not a single snapshot — across security, availability, processing integrity, confidentiality, and privacy.

ISO 27001

The internationally recognized standard for information security management: access control, risk management, incident response, and ongoing monitoring.

The executive summary

Five things to remember.

  1. 01

    Your data is encrypted.

  2. 02

    Your account has its own unique key.

  3. 03

    Access is verified.

  4. 04

    Your information is isolated from other customers.

  5. 05

    The infrastructure is backed by recognized standards.

Built in from day one.

Not as an afterthought.

Your AI employees handle real calls, real customers, and real company knowledge. Every one of them works inside the security model above — and what you teach them is never used to train anyone else’s.

Questions?

Have security questions? Let’s talk.

If you ever have a question about how your data is protected, reach out. Todd is happy to answer it personally.