Skip to main content
Skip to content

Trust center

Everything procurement needs to evaluate us.

Compliance status, sub-processors, data residency, and security documents — without an NDA gate to find them.

SOC 2 Type II readiness · Target Q4 2026 · DPA on request

Compliance

What we attest to

We list frameworks honestly — what is in place, what is in progress, and what is handled by our processor. A SOC 2 Type II readiness program is underway; until the report is issued, control documentation and our security questionnaire response are available under NDA.

In progress

SOC 2 Type II

Readiness program in progress, targeting Q4 2026. Control documentation and policies are available under NDA today.

Ready

GDPR

Data processing agreement available on request. Data subject rights honored. Cross-border transfers covered by Standard Contractual Clauses.

Ready

CCPA & US state privacy

California, Colorado, Connecticut, Virginia, and Utah privacy rights supported. No sale or share of personal information.

Handled by Stripe

PCI DSS

Payments processed by Stripe, a PCI DSS Level 1 service provider. No card data ever touches our servers.

Data

What we do — and don't do — with your data

Four commitments, stated plainly. The architectural detail behind each lives on the Security page.

01

Sensitive data is redacted before storage

Our redaction layer automatically detects and redacts common payment, banking, and personal contact identifiers from call transcripts before storage and analysis. It is on by default — no opt-in required.

02

Your content is not used to train AI models

Anthropic, OpenAI, and AssemblyAI all contractually exclude API data from model training under their commercial terms. Your call content is processed, not learned from.

03

Tenant isolation is enforced by design

Every row of every table is scoped by tenant, with row-level security enforced in the database and privileged access gated against the tenant boundary.

04

Data is hosted in US regions

Primary data stores run in US regions on managed Postgres and US-region AI providers. Standard Contractual Clauses cover any cross-border processing required by integrations or edge delivery.

Sub-processors

The services that process your content

Every service that processes your content, by role, data category, and region. We notify customers in advance of material changes.

Core platform

  • Supabase

    Role

    Primary database, auth, file storage

    Data category

    All tenant data, transcripts (post-redaction), uploaded files

    Region

    US
  • Vercel

    Role

    Application hosting and edge network

    Data category

    HTTP request and response data in transit

    Region

    Global

AI providers

  • Anthropic

    Role

    Claude — call analysis and methodology scoring

    Data category

    Redacted transcript text and structured prompts

    Region

    US
  • OpenAI

    Role

    Embeddings for retrieval (RAG)

    Data category

    Redacted transcript chunks

    Region

    US
  • AssemblyAI

    Role

    Audio transcription

    Data category

    Call audio

    Region

    US
  • ElevenLabs

    Role

    Practice Simulator voice synthesis

    Data category

    Synthetic buyer-turn text

    Region

    US
  • Tavus

    Role

    Practice Simulator avatar video

    Data category

    Synthetic buyer-turn text

    Region

    US

Call ingestion

  • Zoom

    Role

    Call ingestion via customer OAuth

    Data category

    Cloud recordings, meeting metadata

    Region

    US
  • Dialpad

    Role

    Call ingestion via customer OAuth

    Data category

    Call recordings, metadata

    Region

    US
  • GoHighLevel

    Role

    Call ingestion via customer OAuth

    Data category

    Recording URLs, contact metadata

    Region

    US
  • Fireflies

    Role

    Transcript ingestion via customer connection

    Data category

    Customer-supplied transcript text

    Region

    US
  • Fathom

    Role

    Transcript ingestion via customer connection

    Data category

    Customer-supplied transcript text

    Region

    US

Communications

  • SendGrid

    Role

    Transactional email delivery

    Data category

    Recipient email address, email body

    Region

    US
  • DocuSeal

    Role

    E-signature for onboarding agreements

    Data category

    Admin name, email, signed agreement

    Region

    US

Billing

  • Stripe

    Role

    Subscription billing and payment processing

    Data category

    Billing contact, payment metadata (no card data on our servers)

    Region

    US

Supporting infrastructure providers (caching, bot protection, error monitoring) that do not receive call content are disclosed on the complete legal list. See all sub-processors

Documents on request

Everything security review needs

Data Processing Agreement

Signed DPA available on request for any paid customer — see /dpa for terms and request flow.

Security questionnaire response

CAIQ-aligned questionnaire response available under NDA.

Architecture and controls overview

Detailed control documentation covering data flow, encryption, access, and monitoring.

SOC 2 Type II report

Available to customers and prospects under NDA once issued; we will note issuance on this page.

Request the security packet
Architecture

Want the architectural depth?

Encryption, integration verification, prompt-injection defense, and the rest of the security architecture live on the Security page.

See security architecture

Procurement FAQ

Procurement questions, answered

Mid-questionnaire? Send it over — we answer within one business day. security@closeintel.ai

Not yet. A SOC 2 Type II readiness program is in progress, targeting Q4 2026. Until the report is issued we share control documentation, our architecture overview, and a CAIQ-aligned security questionnaire response under NDA.

Yes. A DPA is available on request for any paid customer and covers GDPR, CCPA, and other US state privacy laws. The full terms and request flow are summarized at /dpa; email security@closeintel.ai or use the contact form below to receive the current executable version.

No. Our AI providers — Anthropic, OpenAI, and AssemblyAI — contractually exclude API data from model training under their commercial terms. We process your call content; we do not learn from it.

Primary tenant data runs in US regions on managed Postgres. Edge and bot-protection providers operate globally. The sub-processor table above lists the region for every service that processes your content; the complete legal list at /sub-processors covers supporting infrastructure providers as well.

Production access is least-privilege, MFA-enforced, and logged. Every privileged action is captured in an append-only audit log, and access is promptly revoked when someone leaves.

Email security@closeintel.ai. We typically respond within one business day, investigate every report, and credit researchers when a finding leads to a fix.

Trust, verified

Security review needed?

We provide a security questionnaire response, data processing agreement, and architecture overview on request — usually within one business day.