Last updated 13 September 2026
You are being asked to hand over a list of merchants and let us call them. That is a lot of trust, and "your data is safe with us" is not an answer. Here is how the system is actually built.
Every client runs their own installation with their own database. Not a shared database with a client column — a separate database.
Practically, that means your list cannot appear in another client's search results, cannot be used to enrich another client's records, and cannot be exported by anyone operating a different installation. The isolation is structural rather than a filter somebody has to remember to apply, which is the kind that fails quietly.
Where you bring your own carrier account, it stays in your name and under your control. The numbers we provision for your territory belong to your account, so if you ever leave, your numbers go with you and keep ringing — you are not renting your own phone numbers back from us.
Carrier and voice-provider credentials are not stored in plain text. They are encrypted with AES-256-GCM, using a key derived from a secret unique to your installation.
The consequence worth understanding: a copy of your database, on its own, does not let anyone spend money on your carrier account — and a credential stored for one client cannot be decrypted by another client's installation, even though both run the same software on the same server.
Agents we build are configured to say plainly that they are automated when somebody asks whether they are a bot, an AI, or a real person. They are configured not to claim a referral, an approval, or a lender relationship that does not exist.
This is a data-handling matter as much as a compliance one: an agent that invents a fact about the person it is calling has put wrong information into your CRM, and you will make decisions on it later.
Access to production is limited to the people who operate it. When we help you tune a script we listen to calls on your installation with you, not by taking copies away. We do not use your lists, your call recordings, or your transcripts to train models, and we do not use them to build anything for another client.
| Provider | What they touch |
|---|---|
| Twilio | Call audio in transit, phone numbers, call metadata |
| ElevenLabs | Audio and transcripts for AI voice calls |
| OpenAI | Text of AI conversations, where used for agent reasoning |
| Amazon Web Services | Hosts servers and databases |
| Cloudflare | DNS and traffic routing for the web layer |
If you need a signed data processing agreement, or a sub-processor list as a document for your own compliance file, ask and we will provide it.
You get your data. On request we export your contacts, call history, and recordings in a usable format, and delete them from our systems. Your numbers stay on your carrier account. There is no export fee and no hold-back — a platform that makes leaving painful is telling you something about how confident it is.
We are not SOC 2 certified, we do not hold ISO 27001, and we are not going to imply otherwise with a badge. We are a small team running a focused system, and the description above is what we can actually stand behind.
If your business requires a certified processor, say so early and we will tell you straight whether we are a fit rather than waste your time.
Questions about any of this, or about a setup for your business — use the form on the home page or call (224) 207-4084.
Talk to us ↗