Trust centre

Built for the buyer who asks the hard questions first.

Regulated industries do not take "trust us" for an answer. Data stays resident in India, consent and contact rules are enforced in the dialler before a call is placed, every conversation is scored, and the whole thing runs on an independently certified security base.

Certifications

Independently certified, with more on the way.

CertifiedISO 27001:2022

Information-security management, certified and in hand. Certificate IC-IS-2505161, issued by INTERCERT, valid to 2028.

On the roadmapSOC 2 · ISO 42001

Service-organisation controls and AI-management-system certification on the trust roadmap.

RegulatoryDPDP · TRAI · PCI-DSS

Aligned to India's data-protection, telecom-contact and payment-security regimes.

The controls

Where your data lives, and who can touch it.

ResidencyData resident in India

Customer and call data held in-region on a private cloud footprint; your data trains only your book.

EncryptionEncrypted at rest & in transit

Managed-key encryption at rest and HTTPS in transit, with recordings encrypted and access-controlled.

AccessMFA & VPC isolation

Multi-factor access and network isolation, with role-based access and full access logging.

ConsentEnforced in the dialler

Consent status and contact-hour rules gate the dialler; a non-compliant call cannot be placed.

Audit100% of calls scored

Every conversation recorded, transcribed and scored, so your audit answer is the whole book, not a 5% sample.

PaymentsPCI-DSS handling

Tokenised card capture and PAN suppression, so cardholder data never lingers in a transcript.

How we run it

Monitored, change-controlled, observable.

The platform is hosted on major cloud infrastructure with managed key management, continuous monitoring and alerting across the stack, and change-control discipline on every release. The full sub-processor list and tenancy detail ship in the security pack on request.

What security teams ask
Where is our data stored?

In India, resident by default. Customer and call data stays in-region, encrypted at rest and access-controlled, and what the platform learns on your book improves only your book.

Are you certified, or just aligned?

ISO 27001:2022 certified and in hand, certificate IC-IS-2505161 issued by INTERCERT and valid to 2028; SOC 2 and ISO 42001 are on the roadmap. DPDP, TRAI and PCI-DSS are enforced in how the platform operates.

How is card and payment data handled?

Inside PCI-DSS. Card capture is tokenised and PANs are suppressed, so cardholder data never lingers in a call, transcript or recording.

Who can access recordings?

Only authorised roles, with MFA and full access logging. Recordings are encrypted and access-controlled, and every access is logged for audit.

Can you meet our procurement and DPA requirements?

Yes. We provide a security pack, a data-processing agreement and answers to your assessment as part of onboarding; residency and audit are the default architecture, not add-ons.

Bring your risk team

We'll answer every question on the record.