Platform controls
Encryption
TLS 1.2 or higher protects service traffic in transit. AWS/Supabase-managed AES-256 encryption protects stored platform data and backups.
Access
MFA is enforced across administrative systems. Officer access is bound to registered telephone numbers, and transcript access requires per-access SMS verification.
Isolation and logging
Agency records are logically segregated with database row-level security. Session, administrative, telephony, and transcript-access events are logged.
AI data use
Customer audio, transcripts, and call narratives are not used to train Fast Dial or subprocessor AI models.
Review-ready evidence
Release verification
Application releases are checked against a documented 51-scenario internal QA suite, including safety-critical gates and regression checks. This is an internal control, not an independent certification.
Adversarial testing
Automated internal testing regularly probes prompt extraction, injection, impersonation, webhook forgery, and access-control bypass scenarios. Results and control evidence are available for authorized agency review.
Quarterly controls
Webhook-signature rejection, administrative MFA attestation, and transcript-access controls are re-verified quarterly under the incident-response policy.
Annual exercises
The incident-response policy calls for annual review and at least one tabletop exercise each year.
How a call moves
Infrastructure
Current service providers include Twilio for telephony, ElevenLabs for speech processing, Supabase on AWS for application hosting and database services, Resend for transactional email, and Propio Language Services for live interpretation. Customer platform data is stored and processed in the United States.
Retention and response
Voice audio follows a 30-day rolling deletion cycle by default and can be shortened on request. Audit logs are retained for 12 months. Agency-configurable transcript retention and deletion requests are supported. A formal response policy defines severity, containment, forensics, evidence preservation, post-incident review, and affected-agency notification within 72 hours of confirming a breach involving agency data.
Request the review package
Detailed assessment responses, control evidence, the incident-response policy, and the retention policy are available to authorized agency reviewers.