Security & privacy

Tenant isolation
Every business record carries a business identifier and access is checked on the backend for every request and background job.
Credential encryption
Provider API keys are encrypted at rest with a server-held key and are never returned to the browser — only masked identifiers are shown.
No card storage
We never store card details. Payments are handled by the configured payment gateway.
Audit trails
Logins, permission changes, credit movements, provider funding, AI usage and admin support access are all recorded.
AI boundaries
The assistant answers only from your own verified knowledge, and nothing is sent to a customer without human review.
Voice consent
Voice cloning requires documented consent, profiles can be deleted, and consent plus usage is audited.