Legal
Security
How credentials, audio and tenant data are protected, and how to report a vulnerability.
Not published yet. This document has not been drafted, and we would rather show nothing than show placeholder text that reads like a commitment. If you need it before it is public — for a review or a procurement process — get in touch and we will send the current draft.
What it will cover
| 01 | API keys: Argon2id at rest, shown once, revocable on the next request |
| 02 | Tenant isolation: organization_id on every scoped row, never a join |
| 03 | Encryption in transit and at rest |
| 04 | Vulnerability disclosure and response targets |
One thing that is already true and not waiting on a document: audio you send is never used to train models.