You are handing us your customers calls.

This page is about what we actually do to protect that data — and what we do not claim.

Saudi PDPL CompliantAES-256 & TLS 1.3Tenant Database Isolation99.9% Uptime Cloud
Every production change is recordedWho changed what and when — reviewable, and reversible.

Your calls and your callers data belong to you. We process them on your behalf to run the service only, and never sell or share them with any advertising party.

We do not use your call content to train AI models — not ours, not anyone else’s.

Six practices in place today.

Full tenant isolation

Every business has a separate workspace at the database level. A user in one company cannot reach another company’s data under any circumstance.

Credentials are never displayed

Your system keys are stored encrypted and appear in no interface — not yours, and not our operations team’s.

Role-scoped access

A quality reviewer sees calls but not connection credentials. A company admin sees outcomes but not model settings.

An audit log for every change

Every version published, route changed or permission edited is recorded with who did it and when, and is reviewable.

Retention you set

You choose how long records, transcripts and recordings are kept. Default is 180 days for records and 30 for recordings, deleted automatically after.

Instant stop and a fallback path

One switch pauses the agent and routes every call to your team. And if any system fails, the call reaches a person instead of dropping.

What we do not claim

We do not yet hold SOC 2 or ISO 27001, and we will not claim otherwise. Call recording is optional and enabled per business after reviewing local regulations, because recording law differs by country.

Have custom security or compliance needs?

Our engineering team is ready to discuss NDAs, custom data retention policies, and enterprise security requirements.