Security

Your calls, your data, your rules.

What we do with a call once it ends, where it is stored, and who can reach it.

01Whose SOC 2 audit it is

Runs on SOC 2 Type II–audited infrastructure. Our core providers include LiveKit, Supabase, Cloudflare, Railway, Twilio, OpenAI and Google Cloud, each of which states on its own trust page that it holds a SOC 2 Type II report. Those audits are theirs.

Speechless does not itself hold a SOC 2 report or any other certification, and we will never say otherwise. Not every part of our stack sits on audited infrastructure: our customer web application is hosted separately. If your procurement process needs the sub-processor list naming each provider and what it covers, ask and we will provide it under NDA.

02Encrypted in transit and at rest

Calls, transcripts and recordings are encrypted in transit and at rest. Nothing sits in the clear, on our side or in storage.

03A full record, not a summary

Every call is logged with its complete transcript, the tools the agent called, and the reason the call ended. It is reviewable after the fact rather than reconstructed from memory, and it is kept for as long as your policy says and no longer.

04Your data stays yours

Recordings can live in your own storage rather than ours. Your call data is never used to train a model shared with anyone else, and it is never sold or handed to a third party for their own purposes.

05The agent hands off to a person

Every agent knows when a call needs a human and transfers with the full context, so the caller does not repeat themselves. It never claims to be a person, and it never pretends to have done something it did not do.

06Reporting a vulnerability

Email [email protected] with enough detail to reproduce the issue. We will acknowledge it and tell you what we are doing about it. Please give us a reasonable window to fix it before disclosing publicly.

Thirty minutes on your actual calls, on a live calendar. You can be live in as soon as 14 days.