Security and data handling
The short version: customer audio, transcripts and generated responses stay inside your infrastructure, because we do not operate a service they pass through.
Training data
Fine-tuning happens in an environment you control, or one agreed in writing. We do not train shared models on customer conversations. Your model is yours and is not used to improve anyone else's.
Audit trail
Pinned model versions, logged inputs and outputs, reproducible generation. Designed so that “why did it say that” has an answer months later, to a regulator or an insurer.
Indian regulatory context
The DPDP Act's consent and purpose-limitation obligations are easier to satisfy when personal data never leaves your control. Where RBI or sector-specific localisation expectations apply, an in-country self-hosted deployment removes the cross-border transfer question rather than documenting it.
What we do not claim
[Be explicit here about certifications you do not hold yet, and what you do instead. A security page that implies absent certifications is the fastest way to lose an enterprise deal at review. If you have no SOC 2 or ISO 27001, say so and describe your actual controls.]
This page is a description of our architecture and practices, not legal advice on your obligations.