Stays between you and your customer.

Encryption on every byte, isolation on every workspace, and a standing promise that your conversations are never used to train an AI model.

Encrypted, everywhere.

AES-256 at rest. TLS 1.2+ in transit. Hardware-backed key management. There are no unencrypted endpoints.

Never training data.

Your conversations are not used to train, fine-tune, or improve any AI model. Not by us. Not by any partner.

Isolated, yours.

Workspace-scoped by default, with dedicated infrastructure for Enterprise. Exportable and deletable on demand.

Your data is not training data.

Most policies bury this in a paragraph. Ours is three words: we don't.

Models process your data to run the conversation and your analytics, then it's yours. It's never recycled into anyone's model weights.

We do not Sell your data.
We do not Share your data with third parties for marketing.
We do not Use your conversations to train or fine-tune any AI model.
We do not Benchmark or demo your data to other customers.
We do not Read your data, except for support, and only when you ask us to.

How we protect every byte.

The controls behind every conversation, API call, and row. No marketing, just what we do.

Encryption, everywhere
AES-256 at rest on every byte we store. TLS 1.2+ in transit on every connection. Hardware-backed key management with automatic rotation.
No AI training on your data
Your audio, transcripts, documents, and analytics are never used to train or fine-tune any model, by us or by any partner.
Hardened infrastructure
Tier-1 hyperscale cloud, with 24/7 physical security, redundant power, and DDoS mitigation at the edge.
Identity & access
Google SSO for teams, and scoped API keys with one-click revocation.
Workspace isolation
Every workspace is a logically isolated container. Every read and write is gated by a workspace check.
Application controls
Rate limiting on every public endpoint, input sanitization, and secrets scrubbed from logs and error reports.
Monitoring & incident response
24/7 automated monitoring with alerting that pages engineering in minutes, and graceful failure when a carrier goes down.
Residency, retention, deletion
Enterprise customers pick the region. Retention is configurable, and any agent, conversation, or workspace is deletable and exportable on demand.

Microphone to database, and not a step further.

Exactly what happens from call connect to storage, and where it doesn't go.

Audio leaves the caller's mic or the web widget and travels over TLS 1.2+ on private-backbone fiber. It's processed in memory at the AI boundary and discarded at the end of the session, never written to disk in that form. What gets stored afterward, the transcript, the recording, the analytics, lands in your workspace, encrypted at rest with AES-256. At no point does any of it become a training set for any model, anywhere.

Telephony partners
Twilio and Telnyx, tier-1 global carriers with their own published security programs.
Infrastructure
A hyperscale cloud provider with 24/7 physical security, redundant power, and hardware-backed key management.
AI models
Enterprise model providers under contractual no-retention, no-training commitments.

Honest beats vague, every time.

We don't currently hold independent security certifications, and we won't claim ones we haven't earned. What we offer instead: concrete controls, the kind your compliance program actually depends on.

What we do, today
Encryption at rest (AES-256) and in transit (TLS 1.2+)
A binding commitment that your data is never used to train AI
Workspace isolation with no cross-workspace data access
Scoped, cryptographically stored API keys with audit and revocation
Origin allowlists and authenticated mode for the web widget
Rate limiting and abuse controls on every public endpoint
Detailed audit logging of administrative and authentication events
Data export, retention control, and on-demand deletion
Region-scoped deployments for Enterprise customers
A responsible disclosure program for security researchers
Need a bespoke arrangement? Enterprise buyers get custom DPAs, regional hosting, retention policies, and deletion confirmations.

Common questions.

Procurement questions, answered plainly. Anything else: [email protected].

No. Not us, not any partner, never.
Yes. AES-256 at rest, TLS 1.2+ in transit, with hardware-backed key management.
Tier-1 hyperscale cloud, in the region associated with your account. Enterprise customers pick the region.
Workspace members you've invited, and a small number of Eclatira engineers and support staff under strict access controls. All administrative access is logged.
Only with the operational partners strictly needed to run the service, Twilio and Telnyx for phone, plus our infrastructure provider. None may use your data for their own purposes.
One click in the dashboard or an API call removes it from primary storage. Written deletion confirmation is available to Enterprise.
Yes. Every transcript, recording, and analytics record is exportable via API or dashboard.
Not yet. We'll publish certifications only once they're earned. In the meantime, the controls listed above cover most of what an audit is actually checking for.

Dedicated deployments.

For regulatory, sovereignty, or contractual requirements beyond our standard platform, isolated infrastructure flexible to match your compliance program.

Infrastructure isolation: dedicated data stores and processing capacity for your account.
Regional data residency: choose the geography where your data lives and is processed.
Custom retention: set exactly how long recordings, transcripts, and analytics are kept.
Custom uptime SLAs, tailored to your operational needs.
Custom subdomain, calls.yourbrand.com instead of a shared domain.
A named account contact for security and operational escalations.

Bring us your toughest questionnaire.

A checklist, a DPA draft, or a live security review. Plain answers, in writing, with specifics.