What we can prove, and what we do not claim
Most security pages are a wall of logos. This one is a description of how the system is built, plus a plain list of the certifications we do not hold. You should be able to tell the difference between an architecture and a badge.
Your data is separated by construction, not by convention
Every event we record carries the identity of the contractor it belongs to on the row itself. Separation is a property of the data model, not a filter someone remembers to apply. A query that forgets which contractor it is asking about does not return somebody else’s calls — it returns nothing useful.
Organisations with more than one location are modelled the same way: a parent organisation, its branches, and membership are distinct concepts in the schema. A multi-location operator can see the whole group; a branch sees its own work.
The audit trail is append-only, and that is the point
Our record of what happened is a ledger. Each event is written once under its own permanent identifier, with a timestamp, the contractor it belongs to, what kind of event it was, and where it came from. Entries are added. They are not edited to make a later story tidier.
This is the same ledger our own measurements read from. We are not able to show you a recovery figure that the ledger cannot account for, because the figure is derived from the ledger rather than asserted alongside it. That constraint is deliberate, and it binds us more than it binds you.
Administrative actions in the client portal are recorded separately — what was done, by which signed-in account, from where, and when.
Test traffic is labelled, permanently and visibly
We place calls to our own systems constantly in order to certify them. Every one of those is marked as test traffic at the point it is recorded, and marked test traffic is excluded from anything we measure or bill against. Our own rehearsals can never quietly inflate your numbers.
What we do NOT claim
We hold no third-party security certification. We are not SOC 2 audited. We are not ISO 27001 certified. We are not HIPAA-attested and we are not PCI assessed. If any of those are a hard requirement for you today, we are not the right vendor today, and we would rather you learn that from this page than from a procurement questionnaire six weeks in.
We are also not going to describe ourselves with words like “bank-level” or “military-grade.” Those phrases have no defined meaning and exist to borrow the credibility of an audit nobody performed.
What we will do is answer specific questions specifically. Ask us what happens to a call recording, who can read it, how long it is kept, and what a deletion request actually removes — and you will get a direct answer rather than a badge.
What we handle, stated plainly
The recovery audit works from call metadata — timestamps, durations, numbers, and outcomes. It is not financial data, and we do not ask for banking details, customer payment information, or anything from your accounting system in order to produce it.
Where we hold credentials to reach a system on your behalf, they are stored as secrets rather than as configuration, and they are scoped to the specific integration that needs them.
If you find a problem
Report it to [email protected]. Tell us what you found and how you found it. We will confirm receipt, tell you what we believe the impact is, and tell you when it is fixed. We will not argue that a real finding is out of scope on a technicality.