Security
How your data is handled.
Every control below is a behaviour in the product, described specifically enough for your reviewer to check it.
SOC 2 Type II · audit underway · report shared with every customer before go-live
Trust
Compliance mode.
What changes when compliance mode is on for your organization, and what is true on every account.
- 01
Compliance mode, one way only
PHIPA/HIPAA compliance mode is set per organization and cannot be turned back off. Behaviour that depends on it cannot be relaxed later, by your team or by ours.
- 02
Notifications carry no PHI
With compliance mode on, email and SMS call summaries carry a link and nothing else, and push notifications drop the preview entirely. Lock screens and inboxes are the two places this data most often leaks, so it never goes there.
- 03
Every access recorded
Reads of PHI-bearing records are written to an access log with actor, action, resource, request id, IP address, and timestamp — built to the content specification in PHIPA s. 10.1(4). Owner and admin only, viewable in the app and exportable as CSV.
- 04
Diagnostics log field names only
Field names carry no caller data, so they are logged everywhere. Values are never written to a log line under compliance mode.
- 05
Retention you set, disposal you can prove
Content and recording retention windows are configured per organization. When data is purged, a deletion receipt is written that outlives it — what was disposed of, why, on whose instruction, and how much.
- 06
Recordings behind expiring links
Call recordings live in a private bucket and are served through signed links valid for five minutes. A URL that gets copied into a ticket or an email stops working almost immediately.
- 07
Fails closed
If we cannot resolve which organization a call belongs to, it is treated as compliance-enabled and gets the redacted path. The failure mode is a missing notification preview.
- 08
BAA before your first call
We sign business associate agreements. Talk to us before you sign up so it is in place from the start.
Data
What we store, and for how long.
You set the retention windows. An unset window means the data is kept until you delete it, so nothing is purged without your instruction.
| Data | Where it lives | How long |
|---|---|---|
| Call recordings | Private object storage, served only through signed links | Your recording retention window; unset means kept until deleted |
| Transcripts and summaries | Application database, visible to your organization only | Your content retention window; unset means kept until deleted |
| Contact records | Application database, visible to your organization only | Kept until you delete the contact or the organization |
| PHI access log | Application database, readable by owners and admins | Kept as the custodian record; it outlives the content it describes |
| Deletion receipts | Application database, readable by owners and admins | Kept permanently, so the receipt survives the purge |
| Diagnostic logs | Infrastructure logging | Short operational window, and under compliance mode they carry field names without values |
FAQ
What reviewers ask.
Who can see our calls inside our own organization?
Members of your organization, scoped by their role. The PHI access log and deletion receipts are restricted further, to owners and admins, since those are the custodian records of who looked at what.
Can compliance mode be turned off later?
No. It is a one-way flag resolved at a single choke point in the code, so behaviour that depends on it cannot be relaxed after a review has passed.
What happens if something goes wrong mid-call?
If we cannot resolve which organization a call belongs to, it is treated as compliance-enabled and takes the redacted path. The worst outcome is a missing notification preview.
Which third parties touch a call?
Delivering a phone call requires a telephony carrier, a speech and language model provider, and cloud infrastructure. We name every one of them, with their role and their location, during security review. The list changes, so we do not publish it here.
How do we get an export?
Transcripts, summaries, and the PHI access log export from the app; the access log exports as CSV up to ten thousand rows per request. Ask if you need a bulk export in another shape.
Send us your security questionnaire.
We will answer it in full. Send the BAA as well; it should be in place before your first call is answered.