Security · Compliance · Trust
Built for buyers
who can't be cavalier.
Any team handling client data, contact info, or recordings asks the hard questions first. Here's how we answer them today and what's on the roadmap.
Trust · Compliance posture
Compliance,on the record.
Encryption, retention, and audit-trails are real today. SOC 2 Type II and HIPAA BAA timelines on request from [email protected]. We co-build the certifications path with our first Enterprise customers.
GCP US-region, encrypted
TLS 1.3 in transit. AES-256 at rest. Configurable retention windows by plan, down to 7 days for compliance-sensitive workflows. No third-party model training, ever.
DPA + sub-processor list available
Data Processing Addendum and sub-processor list emailed within 5 business days of request. Full vendor list published on the security page.
SOC 2 + BAA on roadmap
We are not currently SOC 2 audited and we do not currently sign BAAs. Both are on the security roadmap. Email [email protected] for our current timeline.
How we handle your data
The details that matter.
Encryption
TLS 1.3 in transit, AES-256 at rest, GCP-managed keys. Per-tenant key isolation on the Enterprise roadmap.
Data residency
US (us-central1) today. EU (eu-west4) and UK (europe-west2) on the roadmap. Email [email protected] for current regional timeline.
Retention
30 days on Starter, 90 days on Growth, unlimited on Scale. Custom retention windows configurable per workspace, down to 7 days for compliance-sensitive workflows. Auto-purge runs nightly.
Access control
Per-workspace user permissions on every tier. No NeuraVoice employee access to call audio without a documented support ticket. SAML SSO and SCIM on the Enterprise roadmap.
Third-party model training
Your call data is never used to train any LLM. No exceptions on any tier. Documented in every Data Processing Addendum we send before contract sign.
Backups & recovery
GCP-native automatic backups on application data and call recordings. Point-in-time recovery within the retention window above. Cross-region replication on the Enterprise roadmap.
Commitments
What we will not do.
The strongest claim a private company can make is what it refuses to do. Every line below is a policy commitment. If we ever break one, you have the right to terminate, refund, and tell whoever you want.
- We will never sell or share customer call data with advertisers, brokers, or third parties.
- We will never train external LLMs on customer call data.
- We will never grant employee access to call audio without a documented support ticket from the customer.
- We will never claim certifications we do not have.
- We will never publish customer logos, case studies, or volume claims without explicit written consent.
Sub-processors
Every vendor we share data with.
The full list, kept honest. Email [email protected] for a signed copy. Analytics and marketing cookies stay off until you opt in; manage your choices anytime from Cookie preferences in the footer.
Documentation
Read it before you buy.
Two documents linked live. Four sent on request from [email protected].
Privacy policy
Live. GDPR + CCPA + CPRA framework, sub-processor list, DSAR rights.
Terms of service
Live. Governed by Quebec law. Binding when you sign up or sign an MSA.
Data Processing Addendum
Standard DPA covering processor obligations + SCCs. Sent within 5 business days.
Sub-processor list (signed)
Signed PDF of the vendor list above. Sent within 5 business days.
BAA path (HIPAA)
We don't yet sign BAAs. Email us your timeline; we'll share where the path stands.
Security overview
One-page summary for procurement: architecture, encryption, retention, vendors.
Need something not listed? [email protected]
