Security & Trust

Security & Trust

Last updated: August 29, 2026

Call-e records and analyzes your meetings, so protecting that data is fundamental to our product. This page explains, in plain language, how we secure your data and who we share it with. For the legal detail, see our Privacy Policy, Data Processing Addendum, and Sub-processor list.

We don't train AI models on your identifiable data

  • We never train AI models on your identifiable customer data, and we do not build our own models from your recordings or transcripts. Call-e uses third-party AI providers via their APIs to transcribe and analyze meetings.
  • Our AI providers are contractually prohibited from using your data to train their models.
  • We may use de-identified and aggregated data to operate and improve the Services. We de-identify using industry-standard methods, do not attempt to re-identify, bar recipients from re-identifying, and limit this to derived or aggregated data — not raw recordings or transcripts. (Our AI vendors do not train on your data; see Privacy Policy §4.)

Hosting and infrastructure

  • The Services run on a Cloud Service Provider, leveraging industry-standard, geographically redundant infrastructure.
  • Meeting recordings, transcripts, and other customer content are stored in encrypted object storage, and application data is stored in a private, managed relational database with no public network access — all secured using industry-standard security practices.

Encryption

  • In transit: all connections use TLS 1.2 or higher.
  • At rest: data is encrypted using AES-256 (S3 server-side encryption; encrypted RDS storage).

Authentication and access

  • Sign-in is handled by a trusted identity provider using secure authentication methods (for example, email-based magic links/codes and single sign-on (SSO)). Call-e does not store user passwords — authentication credentials are managed by the identity provider.
  • Call-e staff and operator access uses a separate authentication mechanism and is managed by role-based access controls and least-privilege principles.

Tenant isolation

Every customer's data is logically isolated by organization, and every request is scoped to the authenticated organization, so one customer cannot access another's data.

Monitoring and secrets

  • We use centralized logging and monitoring services to monitor reliability, performance, and security signals.
  • Secrets and credentials are managed using dedicated secrets management and infrastructure management systems (with environment separation between production and development) — never hard-coded in source. Automated scanning helps detect accidentally committed secrets and vulnerable dependencies.

Sub-processors

We publish a complete, current list of the third parties that process your data on our Sub-processor list, and we notify customers before adding a new one.

Data retention and deletion

We retain your data for as long as needed to provide the Services and as governed by your agreement. On termination, our default is to de-identify your data using industry-standard, irreversible methods so it cannot reasonably be re-identified, within 30 days, in accordance with our DPA. If you ask us to delete your data, we hard-delete it from our application database and file storage within 30 days of verifying the request. As a standard operating practice, operational logs and routine backups are kept on standard, time-limited retention schedules and age out automatically rather than being individually purged; we also retain data required by law. (We are expanding self-serve export and deletion controls — see Privacy Policy §8.)

Compliance

  • Our security program is built and operated to the SOC 2 (Trust Services Criteria) control set, and we continuously monitor our controls against the SOC 2 framework using automated compliance tooling. The remaining step to certification is the formal third-party audit and observation period, which is in progress. We are completing a SOC 2 Type II examination by an independent auditor and will share the report once available.
  • We support compliance with GDPR/UK GDPR and CCPA/CPRA and offer a Data Processing Addendum.
  • Call-e is not HIPAA-compliant and is not intended for protected health information (PHI). See our Acceptable Use Policy.

Responsible disclosure

Found a security issue? Email security@call-e.io. We appreciate responsible disclosure and will work with you to investigate and resolve valid reports.