Security

Security you can verify

Not declarations but mechanisms: each one can be checked in the database schema or in the code.

A server rack with status lights
Protected at the database level
RLS · 67 tables
AES-256-GCM
Audit log
Mechanisms

Six things that do not depend on discipline

  1. 01

    Data isolation

    RLS in FORCE mode on 67 tables — it applies even to the table owner.

  2. 02

    Key encryption

    AES-256-GCM; the master key is never stored in the database.

  3. 03

    Roles and permissions

    Five roles with different boundaries; the API has per-action permissions.

  4. 04

    Audit log

    Who changed what, when and to what. Append-only, never edited.

  5. 05

    Retention periods

    Records are deleted on schedule — automatically, not by reminder.

  6. 06

    Data subject requests

    Access, deletion, portability — tracked separately with a 30-day deadline.

Isolation

Every customer sees only their own data

Not a filter in a query but a policy of the database itself: without the customer’s ID a query returns nothing.

Subprocessors

Who processes data during a call

LinkWhoWhat they receive
TelephonyYour SIP carrier or your own PBXthe call audio channel
Speech recognitionDeepgramaudio → text
Conversation modelOpenAI or Anthropiccall text → reply
Speech synthesisDeepgram · ElevenLabs · OpenAIreply → voice
Recording storageYour S3-compatible bucketaudio, only if you turned recording on
Demo

Send us your
list of requirements.

We will go through it point by point and say plainly what already exists and what would need work.