Skip to main content

Security

Sales conversations are sensitive. We treat them that way.

This page describes what we have actually built. Where something is only partly done, or we are working towards a standard rather than holding it, we say so.

Data is encrypted while it travels. The full detail is in the privacy policy.

Controls

Six things worth knowing before you send us a call.

Tenant isolation

Enforced at the database

The database itself limits every table to the account that owns it, so keeping accounts apart does not depend on the app getting a filter right.

Personal information

Found and masked before anything is sent

We find personal details on our own systems, with nothing sent outside, using either a standard or a strict setting. Those details are swapped for stand-in labels before any transcript goes to an AI provider.

Raw values

Keep, quarantine or shred

Each account decides what happens to the original detail. If it is kept, access is restricted and the stand-in label is used everywhere else. We do not describe this as strong encryption.

Access

Checked on our servers, and refused if unsure

We check who you are on our own servers and never take the browser's word for it. If the check cannot be completed, the request is refused.

API tokens

Hashed, scoped and revocable

API tokens are never stored in readable form. They are limited to what you allow, and you can cancel them at any time from the app.

Sub-processors

Named, with no-training commitments

Every company that handles your data is listed in the privacy policy, along with their promise not to train on it.

Being precise

What we do not claim.

Not certified. We build to the areas ISO 27001 and SOC 2 cover, and we are working towards being ready. We do not hold either certificate and we will not pretend otherwise.

Stand-in labels, not strong encryption. Personal details we keep so they can be matched up later are hidden and access is restricted. That is not the same as strong encryption, and we will not call it that.

Deleting data is done by a person. Removal happens on a reviewed schedule, run by an administrator, rather than automatically. If you need data gone sooner, ask and we will do it.

Send security review questions our way.

If you need a security questionnaire filled in before a trial, we would rather do it up front.