Trust center

Built for agency review.

Clear controls, named subprocessors, documented retention, and a formal incident-response process—without overstating certifications.

Certification boundary: Fast Dial, Inc. d/b/a City919 does not currently hold its own SOC 2 report. EMT919 is built on SOC 2-certified provider infrastructure. Provider certifications apply to the named providers.

Platform controls

Encryption

TLS 1.2 or higher protects service traffic in transit. AWS/Supabase-managed AES-256 encryption protects stored platform data and backups.

Access

MFA is enforced across administrative systems. Officer access is bound to registered telephone numbers, and transcript access requires per-access SMS verification.

Isolation and logging

Agency records are logically segregated with database row-level security. Session, administrative, telephony, and transcript-access events are logged.

AI data use

Customer audio, transcripts, and call narratives are not used to train Fast Dial or subprocessor AI models.

Review-ready evidence

Release verification

Application releases are checked against a documented 51-scenario internal QA suite, including safety-critical gates and regression checks. This is an internal control, not an independent certification.

Adversarial testing

Automated internal testing regularly probes prompt extraction, injection, impersonation, webhook forgery, and access-control bypass scenarios. Results and control evidence are available for authorized agency review.

Quarterly controls

Webhook-signature rejection, administrative MFA attestation, and transcript-access controls are re-verified quarterly under the incident-response policy.

Annual exercises

The incident-response policy calls for annual review and at least one tabletop exercise each year.

How a call moves

Authorized agency phoneTwilio telephonySpeech and application servicesTranslated audio or live interpreter

Infrastructure

Current service providers include Twilio for telephony, ElevenLabs for speech processing, Supabase on AWS for application hosting and database services, Resend for transactional email, and Propio Language Services for live interpretation. Customer platform data is stored and processed in the United States.

Retention and response

Voice audio follows a 30-day rolling deletion cycle by default and can be shortened on request. Audit logs are retained for 12 months. Agency-configurable transcript retention and deletion requests are supported. A formal response policy defines severity, containment, forensics, evidence preservation, post-incident review, and affected-agency notification within 72 hours of confirming a breach involving agency data.

Request the review package

Detailed assessment responses, control evidence, the incident-response policy, and the retention policy are available to authorized agency reviewers.

Request security materials