You're trusting us with your business — and your customers' information. We take that seriously, and we build with privacy and security in mind from the ground up.
Data is encrypted in transit with TLS and at rest, so information stays protected whether it's moving or stored.
Access to customer data is restricted to what's necessary, protected by authentication and internal controls.
We run on reputable cloud providers with monitoring, automatic backups, and a 99.9% uptime target.
Your data is yours. You can export it, and we don't sell personal information. See our Privacy Policy.
Every call and conversation is logged and readable, so you always know what your assistant said and did.
The vendors we rely on — for hosting, telephony, and payments — are established providers with their own strong security programs.
We design our practices around leading security and privacy frameworks. As a growing company, we're transparent about where we are: the items below describe the standards our practices are modeled on and, where noted, that we are actively working toward formal attestation.
Controls for security, availability, and confidentiality modeled on SOC 2. Formal report: in progress.
Information-security management modeled on the ISO 27001 framework.
Data-subject rights and processing practices designed to meet GDPR / UK GDPR expectations.
Safeguards for healthcare Customers handling PHI, with BAAs available where applicable.
Need documentation for a vendor review or a BAA? Contact our security team. (Edit these statements to match your actual certification status.)
When we operate an assistant for your business, we process the calls, chats, and details involved so we can book appointments, follow up, and give you a record of what happened. We use that information to provide and improve the Services — not to sell it. Full details are in our Privacy Policy.
Automated texts follow opt-in and opt-out best practices, and recipients can always reply STOP. Where call recording is enabled, it's subject to applicable law, and you remain responsible for any notices or consents your jurisdiction requires. We can help you configure the Services to match your compliance needs.
We welcome responsible disclosure. If you believe you've found a security issue, please email truevorra@gmail.com with the details and steps to reproduce. Please don't access or modify data that isn't yours, and give us a reasonable chance to respond before any public disclosure. We're grateful for the help.
We're happy to walk your team through how we protect data, and to provide documentation for vendor reviews.