TRAINYOURAGENT

Our security posture, in plain English.

Security pages usually list aspirations. This one separates what is enforced today from what is on the roadmap, because a buyer's diligence call will find the gap anyway and it is cheaper to say it first. Data location, access control, credential handling, and incident response, in that order.

Where data lives and who can reach it

Customer transcripts and knowledge bases sit in per-tenant storage with row-level isolation. Access is limited to the engineers on that build, authenticated through SSO with hardware-key second factor. Third-party model providers process call content in transit under their enterprise terms and are listed on the sub-processors page rather than left implicit.

Enforced today

Not yet true

There is no SOC 2 Type II report. There is no third-party penetration test on file. Both are honest gaps rather than pending items with an invented date, and if either is a hard requirement for your procurement process, that is a reason to wait rather than a reason to sign. Healthcare builds do run under a signed BAA today.

How an incident would be handled

Detection through provider alerting and error-rate monitors, containment by revoking the affected credential set, notification to affected customers within seventy-two hours with what we know and what we do not, and a written post-mortem. Small enough to be handled directly by the person who built the system, which is both the strength and the limit of it.