How the protection works

How we protect your call recordings

Where the audio lives, how your integration keys are encrypted, who inside the company can open which calls, and what happens to the data if you decide to leave.

The foundation

4 safeguards that work by default

Encrypted at rest and in transit Audio is stored in encrypted, S3 compatible Backblaze B2 storage. The channel to and from it is closed.
Integration keys under AES-256-GCM Your phone system and CRM access keys are encrypted separately and never stored in the clear.
Every company isolated Multi-tenant at the data schema level. One company's query technically cannot reach another's calls.
Your conversations never train models Data is processed for your workspace and stays inside it.

The path a recording takes

What happens to a file between the phone system and the dashboard

01 Intake

The phone system's webhook is checked against a secret. A request without the right signature creates no call.

02 Retention

The audio is uploaded to encrypted storage. File links are signed and short-lived.

03 Processing

Transcription and analysis happen inside your workspace. The result is bound to your company.

04 Access

Only the roles that should see data can see it. Every request is token checked.

Access

A rep never sees anyone else's calls

This is not a setting you have to remember to switch on. It is how the roles work by default.

  • Token authentication on every request
  • Rate limiting on the API
  • Secret checking on inbound webhooks
  • SSO on the Enterprise plan
RoleWhat they see
OwnerThe whole company, the team, integrations, billing
AdminThe whole company, the team, integrations
Sales repOnly their own calls and their own metrics
CoachTeam analytics for coaching
AnalystData and export

Retention and deletion

The data is yours — you can take it at any time

7 daysrecording retention on the free plan
No limitretention on Pro, for as long as the subscription runs
CSVexport calls and metrics at any time
On requestcomplete deletion of your company's data
What is worth agreeing inside your own team Recording conversations is governed by law and by your own internal rules. Telling the customer a call is recorded, how long it is kept, and the lawful basis for processing all remain your company's responsibility as the data owner. Our own role as the service is set out in the DPA.

Security questions

Need something for your legal or security team?

Tell us which documents you need and we will send what exists, without vague language.