- Tenant isolation
- Every business record carries a business identifier and access is checked on the backend for every request and background job.
- Credential encryption
- Provider API keys are encrypted at rest with a server-held key and are never returned to the browser — only masked identifiers are shown.
- No card storage
- We never store card details. Payments are handled by the configured payment gateway.
- Audit trails
- Logins, permission changes, credit movements, provider funding, AI usage and admin support access are all recorded.
- AI boundaries
- The assistant answers only from your own verified knowledge, and nothing is sent to a customer without human review.
- Voice consent
- Voice cloning requires documented consent, profiles can be deleted, and consent plus usage is audited.