Security and compliance

Where conversation data lives, how long it stays, who can read it.

This page states how we handle customer conversation data — storage, retention, access — and the material internal audit and legal review usually ask for.

Last updated July 2026 · Ask us for the full security white paper

Transit and storage

Encrypted end to end, with keys managed apart from business data.

  • TLS 1.2+ in transit
  • AES-256 at rest
  • Separate key custody and rotation

Access and permissions

Least privilege, with every access recorded.

  • Role tiers and data isolation
  • Two-person review for admin actions
  • 12-month login and action logs

Audit and delivery

Review material exports directly, without manual collation.

  • Conversation and log export
  • DPA template
  • Pen-test summary and remediation record

Data classes and retention

Defaults shown. Under private deployment, storage location and retention are set by the customer.

Data classStorageDefault retentionWho can access
Conversation contentRegional data centre (Singapore / Frankfurt)Long-term, policy-based cleanupAuthorised agents and admins
Translation intermediatesMemory and temporary cache24 hoursSystem processes only
Customer records and tagsRegional data centreAccount lifetimeAuthorised agents and admins
Action logsSeparate log store12 monthsAdmin and audit roles (read-only)
Account credentialsKey management serviceAccount lifetimeSystem processes, export blocked

A few hard internal rules.

Security is process, not only features. These rules apply to our engineering and support teams and are enforced internally.

No production data locallyEngineering and support may not export production conversations to personal devices.
Time-boxed accessTroubleshooting requires customer authorisation; access lasts at most 8 hours and auto-revokes.
Traceable changesEvery production change goes through review and a release record attributable to a person.
Regular drillsQuarterly recovery and failover drills, with reports retained.
Vendor reviewThird-party services such as translation are assessed, and data passed is minimised.

Need a security questionnaire or white paper?

We can complete security questionnaires, provide a DPA template and a penetration test summary for your procurement and legal process.

Get the compliance packFAQ