Security · Compliance · Trust

Built for buyers
who can't be cavalier.

Any team handling client data, contact info, or recordings asks the hard questions first. Here's how we answer them today and what's on the roadmap.

Trust · Compliance posture

Compliance,on the record.

Encryption, retention, and audit-trails are real today. SOC 2 Type II and HIPAA BAA timelines on request from [email protected]. We co-build the certifications path with our first Enterprise customers.

GCP US-region, encrypted

TLS 1.3 in transit. AES-256 at rest. Configurable retention windows by plan, down to 7 days for compliance-sensitive workflows. No third-party model training, ever.

DPA + sub-processor list available

Data Processing Addendum and sub-processor list emailed within 5 business days of request. Full vendor list published on the security page.

SOC 2 + BAA on roadmap

We are not currently SOC 2 audited and we do not currently sign BAAs. Both are on the security roadmap. Email [email protected] for our current timeline.

How we handle your data

The details that matter.

Encryption

TLS 1.3 in transit, AES-256 at rest, GCP-managed keys. Per-tenant key isolation on the Enterprise roadmap.

Data residency

US (us-central1) today. EU (eu-west4) and UK (europe-west2) on the roadmap. Email [email protected] for current regional timeline.

Retention

30 days on Starter, 90 days on Growth, unlimited on Scale. Custom retention windows configurable per workspace, down to 7 days for compliance-sensitive workflows. Auto-purge runs nightly.

Access control

Per-workspace user permissions on every tier. No NeuraVoice employee access to call audio without a documented support ticket. SAML SSO and SCIM on the Enterprise roadmap.

Third-party model training

Your call data is never used to train any LLM. No exceptions on any tier. Documented in every Data Processing Addendum we send before contract sign.

Backups & recovery

GCP-native automatic backups on application data and call recordings. Point-in-time recovery within the retention window above. Cross-region replication on the Enterprise roadmap.

Commitments

What we will not do.

The strongest claim a private company can make is what it refuses to do. Every line below is a policy commitment. If we ever break one, you have the right to terminate, refund, and tell whoever you want.

  • We will never sell or share customer call data with advertisers, brokers, or third parties.
  • We will never train external LLMs on customer call data.
  • We will never grant employee access to call audio without a documented support ticket from the customer.
  • We will never claim certifications we do not have.
  • We will never publish customer logos, case studies, or volume claims without explicit written consent.

Sub-processors

Every vendor we share data with.

The full list, kept honest. Email [email protected] for a signed copy. Analytics and marketing cookies stay off until you opt in; manage your choices anytime from Cookie preferences in the footer.

VendorPurpose
Google CloudHosting, compute, application data, secrets, AI inference (us-central1)
TwilioTelephony, SMS, voice transport
StripeSubscription billing, payment processing
CloudflareCDN, DDoS protection, Turnstile (anti-abuse)
FirebaseUser authentication and identity
SendGridTransactional and marketing email delivery
PostHogProduct analytics and session replay (consent-gated)
Cal.comDemo scheduling and bookings