Trust

Built for calls
you can defend.

Voice agents handle real conversations with real people. Below is exactly what we do to keep that data safe, how consent and AI disclosure are gated, and — just as importantly — what we do not claim. No compliance theatre.

01Posture

What's in place today.

01

Built on audited infrastructure

The speech engines, model inference and storage run on SOC 2 Type II-audited cloud processors. We inherit their controls; we do not claim our own SOC 2 or HIPAA certification and won't pretend otherwise.

02

Zero-retention processing

Available on request: audio and transcripts are processed in-memory for the live call and not persisted beyond it. When you don't need recordings kept, they aren't kept.

03

GDPR & DPAs

We sign a Data Processing Agreement as your processor, with Standard Contractual Clauses for international transfers. You stay the controller of the personal data inside your calls.

04

EU-resident storage

Enterprise workspaces can pin call storage and processing to an EU region, so recordings and transcripts never leave the bloc. In-region MENA options are scoped per contract.

05

Encryption everywhere

TLS in transit, encryption at rest, recordings behind short-lived signed URLs, API keys stored hashed, and webhook deliveries signed so you can verify origin.

06

Least-privilege access

Production access is restricted, logged and audited. Every key is scoped to one organization; cross-org IDs return a 404, not a 403 — other tenants are invisible.

02Consent & disclosure

Consent and AI disclosure, gated at the agent.

A voice agent that doesn't tell people it's AI — or records without a basis — is a legal problem waiting to happen. So the guardrails live in the agent config, not a policy PDF.

01

AI-disclosure gate

Agents can be required to disclose they're an AI at the start of the call — configurable per agent, and on by default. Callers know who they're talking to.

02

Recording-consent gate

When recording is on, the agent can be required to announce it and capture consent before anything is stored — with the moment logged against the call.

03

PDPL-aware (UAE & KSA)

Consent and notice defaults are built with the UAE and Saudi Personal Data Protection Laws in mind — the jurisdictions most of our callers sit in.

04

TDRA-aware outreach

Outbound campaigns respect calling-time windows and disclosure norms in line with UAE TDRA expectations. You warrant a lawful basis to call; we give you the controls to do it right.

03Boundaries

What we don't do.

  • We don't claim our own SOC 2 or HIPAA certification — we build on processors that hold them.
  • We don't train models on your call audio, transcripts, or analysis outputs.
  • We don't sell call data, ever.
  • We don't identify callers biometrically or store voiceprints across calls.
  • We don't place calls without a phone number and agent you configured and published.

The full detail lives in the legal pages — written for compliance teams, not marketers.

Need a DPA or a security review?.

Engineers answer the security inbox. Ask for the subprocessor list, a DPA, or data-residency options.