Your data stays in the EU, your AI answers carry a named human's approval, and every action is recorded. Security here is not a badge; it is how the product works.
Your conversations, contacts and files are hosted in the EU. A current sub-processor list is available on request, so your legal team can see exactly who touches your data before they sign anything.
Connect your own AWS SES and outbound email runs through an account you own and control, in the region you chose. Telephony and voice credentials are stored and verified today, but provisioning still runs on our accounts — we would rather tell you that than let your legal team assume otherwise.
Where the model applies, you hold the key in your own account and the data path runs through your infrastructure rather than being pooled with anyone else's. Revoke the key and the connection stops the same minute.
The audit trail is a security control, not just a log. Every reply records who sent it, and a draft sent unedited also keeps the fact number it was built from and the model's confidence; edit the draft and it is recorded as that person's own words. No answer is anonymous, and any message a customer received traces back to the person who stood behind it.
You set retention rules for how long conversations are kept. You can export your data and delete it on request, and a signed Data Processing Agreement is available for teams that need one on file.
The AI always drafts, and it sends only what a human has approved. The single exception is a mailbox you have deliberately opted into autonomy, and only for the narrow, safe intents you defined.
It will never send anything involving money, legal commitments or cancellations without a human approving it first. Those decisions stay with a person, every time.