Platform · Security
Nothing leaves your
perimeter that you did
not decide to send.
The runtime, the models and the observability store run where you deploy them. No third-party model hears your callers, and no transcript trains a model anyone else uses.
- The boundary you chooseOn-premises, cloud or region
- Audio and transcriptsRetention is yours, to zero
- Model weightsYours to tune, never shared
- Every turn on recordExports to your monitoring
- Your roles, your APIsWrites only what you permit
- Inside your perimeter
- No third-party model
- Zero-retention mode
Everything a call produces stays on your side of the boundary.
Audio, models and records share one deployment boundary, drawn where you deploy. Retention, training and access are your settings, not ours.
Audio and transcripts
Processed inside your boundary, kept as long as you decide.
Model weights and training
Tuned on your side. Your calls improve no one else's model.
Systems of record
Read and written through your APIs, under your own roles.
One detail, followed
A caller reads out a card number. Here is everywhere it goes.
One risk, one control, and its proof.
Each row is a risk your review will raise, in the words it uses. The control beside it is the one we deploy, and the evidence line names what we send.
- A card number is in a transcript
- Call data leaves your perimeter
- An agent acts without authority
- A vendor's model hears the call
- You cannot prove what happened
RiskA card number is in a transcript
Sensitive details are masked at capture, and regulated call types retain nothing.
How it is enforced
Masking runs in the capture path, before a transcript is written, and the retention rule for each call type is a setting you hold.
EvidenceRedaction policy on request
RiskA card number is in a transcript
Sensitive details are masked at capture, and regulated call types retain nothing.
How it is enforced
Masking runs in the capture path, before a transcript is written, and the retention rule for each call type is a setting you hold.
EvidenceRedaction policy on request
RiskCall data leaves your perimeter
Air-gapped on your premises, or in one region you name. Nothing leaves by design.
How it is enforced
The runtime, the models and the stores are deployed inside your network, and the rule that would let anything out is yours to write.
EvidenceDeployment architecture diagram on request
RiskAn agent acts without authority
Policy is checked before any action runs. Anything outside it goes to a person.
How it is enforced
Your policy names the actions an agent may take and the arguments it may pass; anything outside it is refused and handed to a person.
EvidenceUnder 0.5% hallucination rate
RiskA vendor's model hears the call
No third-party model is in the call path. Every model runs inside your boundary.
How it is enforced
Speech, language and voice models ship with the runtime and run on your compute, so the call path calls no one else's endpoint.
EvidenceModel inventory on request
RiskYou cannot prove what happened
Every turn, action and write is recorded, and the record exports to your monitoring.
How it is enforced
Each turn, tool call and write is stamped with the actor and the tool as it happens, so the record is made while the call is running.
EvidenceRedacted trace export on request
Every framework your review names, and the mark beside it.
The frameworks your questionnaire asks about, each with its own mark beside it. The reports come under NDA.
ISO 27001:2022
Information security
SOC 2 Type 1
How controls are designed
SOC 2 Type 2
How controls run over time
PCI DSS
Cardholder data
HIPAA
Protected health information
GDPR and CCPA
EU and California privacy
ISO 42001:2023
Management system for AI
DORA
Operational resilience
ISO 17442:2020
Legal entity identifier
Your review team needs the paper, not the logo. The scope, the issuer, the reference and the expiry for each one travel in the package, beside the answers to your questionnaire.
Request the security packageYour questionnaire, answered in your format.
The package is the architecture diagram, the data-flow inventory and the attestation context, the same documents we deploy from, not a marketing deck.
Send the questionnaire you already use. It comes back answered line by line.
The security package, opened
Eight documents, each one answering a question above.
Bring one call type. Leave with an architecture.

One perimeter, drawn where your data lives
A working session with an engineer who has deployed inside a bank’s perimeter. We map your telephony, data boundary and handoff rules, and tell you what we would not automate.