Information-security management, certified and in hand. Certificate IC-IS-2505161, issued by INTERCERT, valid to 2028.
Built for the buyer who asks the hard questions first.
Regulated industries do not take "trust us" for an answer. Data stays resident in India, consent and contact rules are enforced in the dialler before a call is placed, every conversation is scored, and the whole thing runs on an independently certified security base.
Independently certified, with more on the way.
Service-organisation controls and AI-management-system certification on the trust roadmap.
Aligned to India's data-protection, telecom-contact and payment-security regimes.
Where your data lives, and who can touch it.
Customer and call data held in-region on a private cloud footprint; your data trains only your book.
Managed-key encryption at rest and HTTPS in transit, with recordings encrypted and access-controlled.
Multi-factor access and network isolation, with role-based access and full access logging.
Consent status and contact-hour rules gate the dialler; a non-compliant call cannot be placed.
Every conversation recorded, transcribed and scored, so your audit answer is the whole book, not a 5% sample.
Tokenised card capture and PAN suppression, so cardholder data never lingers in a transcript.
Monitored, change-controlled, observable.
The platform is hosted on major cloud infrastructure with managed key management, continuous monitoring and alerting across the stack, and change-control discipline on every release. The full sub-processor list and tenancy detail ship in the security pack on request.
Where is our data stored?
In India, resident by default. Customer and call data stays in-region, encrypted at rest and access-controlled, and what the platform learns on your book improves only your book.
Are you certified, or just aligned?
ISO 27001:2022 certified and in hand, certificate IC-IS-2505161 issued by INTERCERT and valid to 2028; SOC 2 and ISO 42001 are on the roadmap. DPDP, TRAI and PCI-DSS are enforced in how the platform operates.
How is card and payment data handled?
Inside PCI-DSS. Card capture is tokenised and PANs are suppressed, so cardholder data never lingers in a call, transcript or recording.
Who can access recordings?
Only authorised roles, with MFA and full access logging. Recordings are encrypted and access-controlled, and every access is logged for audit.
Can you meet our procurement and DPA requirements?
Yes. We provide a security pack, a data-processing agreement and answers to your assessment as part of onboarding; residency and audit are the default architecture, not add-ons.