SECURITY & COMPLIANCE

Compliance, built in from day one.

Not an afterthought. Every conversation, every recording, every transcript moves through the same standard of care - wherever in the world it happens.

Where each framework stands

We would rather tell you the honest status than show a badge we have not earned. This table is kept current.

FrameworkScopeStatusNotes
GDPREU / UK personal dataIn placeData-handling practices in place: lawful basis, consent capture, retention limits, subject-access handling.
DPDP Act (India)Indian personal dataIn placeConsent notices, purpose limitation, and data-principal rights handled in line with the Digital Personal Data Protection Act.
SOC 2Security, availability, confidentialityIn progressControls being implemented; independent audit not yet completed. No SOC 2 mark is displayed until an unqualified opinion is issued.
ISO 27001Information security managementIn progressISMS being documented in parallel with the pilot program.
HIPAAUS health informationIn progressRelevant only for healthcare studies; safeguards being assessed. Not yet certified.

Technical controls

  • Encryption in transit and at rest for recordings, transcripts, and scores.
  • Role-based access so researchers, analysts, and clients see only what their role needs.
  • Audit trail per conversation: every score and flag can be traced back to the exchange that produced it.
  • Voice verification without biometrics: repeat respondents are detected without storing a voice profile.
  • Fraud and bot detection and duplicate-respondent flagging on every study.

Data handling in a conversation

Respondents are told at the start of every conversation that they are speaking with an AI interviewer, what is recorded, and how to withdraw. Recordings and transcripts are retained only for the period agreed in the study scope and are deleted on request. See the privacy policy for the full notice.

Questions

Security questionnaires, sub-processor lists, and DPAs are available on request during the pilot process.