Security

How your data is handled.

Every control below is a behaviour in the product, described specifically enough for your reviewer to check it.

SOC 2 Type II · audit underway · report shared with every customer before go-live

Trust

Compliance mode.

What changes when compliance mode is on for your organization, and what is true on every account.

  • 01

    Compliance mode, one way only

    PHIPA/HIPAA compliance mode is set per organization and cannot be turned back off. Behaviour that depends on it cannot be relaxed later, by your team or by ours.

  • 02

    Notifications carry no PHI

    With compliance mode on, email and SMS call summaries carry a link and nothing else, and push notifications drop the preview entirely. Lock screens and inboxes are the two places this data most often leaks, so it never goes there.

  • 03

    Every access recorded

    Reads of PHI-bearing records are written to an access log with actor, action, resource, request id, IP address, and timestamp — built to the content specification in PHIPA s. 10.1(4). Owner and admin only, viewable in the app and exportable as CSV.

  • 04

    Diagnostics log field names only

    Field names carry no caller data, so they are logged everywhere. Values are never written to a log line under compliance mode.

  • 05

    Retention you set, disposal you can prove

    Content and recording retention windows are configured per organization. When data is purged, a deletion receipt is written that outlives it — what was disposed of, why, on whose instruction, and how much.

  • 06

    Recordings behind expiring links

    Call recordings live in a private bucket and are served through signed links valid for five minutes. A URL that gets copied into a ticket or an email stops working almost immediately.

  • 07

    Fails closed

    If we cannot resolve which organization a call belongs to, it is treated as compliance-enabled and gets the redacted path. The failure mode is a missing notification preview.

  • 08

    BAA before your first call

    We sign business associate agreements. Talk to us before you sign up so it is in place from the start.

Data

What we store, and for how long.

You set the retention windows. An unset window means the data is kept until you delete it, so nothing is purged without your instruction.

Data Where it lives How long
Call recordings Private object storage, served only through signed links Your recording retention window; unset means kept until deleted
Transcripts and summaries Application database, visible to your organization only Your content retention window; unset means kept until deleted
Contact records Application database, visible to your organization only Kept until you delete the contact or the organization
PHI access log Application database, readable by owners and admins Kept as the custodian record; it outlives the content it describes
Deletion receipts Application database, readable by owners and admins Kept permanently, so the receipt survives the purge
Diagnostic logs Infrastructure logging Short operational window, and under compliance mode they carry field names without values

FAQ

What reviewers ask.

Who can see our calls inside our own organization?

Members of your organization, scoped by their role. The PHI access log and deletion receipts are restricted further, to owners and admins, since those are the custodian records of who looked at what.

Can compliance mode be turned off later?

No. It is a one-way flag resolved at a single choke point in the code, so behaviour that depends on it cannot be relaxed after a review has passed.

What happens if something goes wrong mid-call?

If we cannot resolve which organization a call belongs to, it is treated as compliance-enabled and takes the redacted path. The worst outcome is a missing notification preview.

Which third parties touch a call?

Delivering a phone call requires a telephony carrier, a speech and language model provider, and cloud infrastructure. We name every one of them, with their role and their location, during security review. The list changes, so we do not publish it here.

How do we get an export?

Transcripts, summaries, and the PHI access log export from the app; the access log exports as CSV up to ten thousand rows per request. Ask if you need a bulk export in another shape.

Send us your security questionnaire.

We will answer it in full. Send the BAA as well; it should be in place before your first call is answered.

We use cookies to see how people use this site (PostHog and Google Analytics) and to measure our ads on Meta and Instantly (Leadsy). Cookies the site needs to work are always on. You can change your choice anytime from Cookie settings at the bottom of the page. Privacy policy

Cookie settings

Choose which cookies we can use. Your choice is saved in a cookie on this browser for 12 months.

Necessary Protect the book-a-call form from bots (Cloudflare Turnstile), remember your light or dark theme, and store your cookie choice. Always on

Book a call

Leave your details and we’ll reach out to set up a time.