01
Encryption
AES-256 at rest, TLS 1.3 in transit. Call recordings and attachments are encrypted with per-workspace keys.
Security
Your customers trust you with order numbers, addresses and phone calls. Here’s how we protect them — from the data center to the AI.
Primary in Paris, backups in Frankfurt.
DPA included on every plan.
Report available under NDA.
Certified information security.
Practices
01
AES-256 at rest, TLS 1.3 in transit. Call recordings and attachments are encrypted with per-workspace keys.
02
SSO with SAML and SCIM provisioning, enforced two-factor login, and roles that limit who sees which inbox.
03
Every sign-in, export, setting change and AI hand-off is logged and exportable to your SIEM.
04
Set retention per channel. Customer erasure requests delete a contact across every channel in one action.
05
Isolated production network, least-privilege access for staff, and encrypted daily backups tested monthly.
06
Annual third-party penetration tests and a public bug bounty. Summaries shared with customers on request.
AI & your data
Prompts and replies are not stored or used for training.
Card numbers, IBANs and IDs are masked before any model sees them.
Each AI agent only reads the articles and tools you allow.
Every AI reply cites its source and is kept in the thread.
Subprocessors
Updated 1 Sep 2026 · 30 days’ notice before changes
| Provider | Purpose | Location |
|---|---|---|
| Scaleway | Application hosting & databases | Paris, FR |
| Amazon Web Services | Encrypted backups | Frankfurt, DE |
| Meta Platforms | WhatsApp Business Platform | Dublin, IE |
| Twilio | Phone numbers & voice calls | Dublin, IE |
| Postmark | Transactional & inbound email | EU region |
| Stripe | Billing & payments | Dublin, IE |
SOC 2 report, pen test summary, DPA and our completed security questionnaire.
We respond within 24 hours and reward valid findings through our bug bounty.
[email protected]Contact us to request our PGP key before sending sensitive details.