Trust center
Everything procurement needs to evaluate us.
Compliance status, sub-processors, data residency, and security documents — without an NDA gate to find them.
SOC 2 Type II readiness · Target Q4 2026 · DPA on request
“Sure — the card ending and my cell is , billing address .”
- PII stripped before storage
- Never used for model training
Compliance
What we attest to
We list frameworks honestly — what is in place, what is in progress, and what is handled by our processor. A SOC 2 Type II readiness program is underway; until the report is issued, control documentation and our security questionnaire response are available under NDA.
SOC 2 Type II
Readiness program in progress, targeting Q4 2026. Control documentation and policies are available under NDA today.
GDPR
Data processing agreement available on request. Data subject rights honored. Cross-border transfers covered by Standard Contractual Clauses.
CCPA & US state privacy
California, Colorado, Connecticut, Virginia, and Utah privacy rights supported. No sale or share of personal information.
PCI DSS
Payments processed by Stripe, a PCI DSS Level 1 service provider. No card data ever touches our servers.
Data
What we do — and don't do — with your data
Four commitments, stated plainly. The architectural detail behind each lives on the Security page.
Sensitive data is redacted before storage
Our redaction layer automatically detects and redacts common payment, banking, and personal contact identifiers from call transcripts before storage and analysis. It is on by default — no opt-in required.
Your content is not used to train AI models
Anthropic, OpenAI, and AssemblyAI all contractually exclude API data from model training under their commercial terms. Your call content is processed, not learned from.
Tenant isolation is enforced by design
Every row of every table is scoped by tenant, with row-level security enforced in the database and privileged access gated against the tenant boundary.
Data is hosted in US regions
Primary data stores run in US regions on managed Postgres and US-region AI providers. Standard Contractual Clauses cover any cross-border processing required by integrations or edge delivery.
Sub-processors
The services that process your content
Every service that processes your content, by role, data category, and region. We notify customers in advance of material changes.
Core platform
- Supabase
Role
Primary database, auth, file storage
Data category
All tenant data, transcripts (post-redaction), uploaded files
Region
US - Vercel
Role
Application hosting and edge network
Data category
HTTP request and response data in transit
Region
Global
AI providers
- Anthropic
Role
Claude — call analysis and methodology scoring
Data category
Redacted transcript text and structured prompts
Region
US - OpenAI
Role
Embeddings for retrieval (RAG)
Data category
Redacted transcript chunks
Region
US - AssemblyAI
Role
Audio transcription
Data category
Call audio
Region
US - ElevenLabs
Role
Practice Simulator voice synthesis
Data category
Synthetic buyer-turn text
Region
US - Tavus
Role
Practice Simulator avatar video
Data category
Synthetic buyer-turn text
Region
US
Call ingestion
- Zoom
Role
Call ingestion via customer OAuth
Data category
Cloud recordings, meeting metadata
Region
US - Dialpad
Role
Call ingestion via customer OAuth
Data category
Call recordings, metadata
Region
US - GoHighLevel
Role
Call ingestion via customer OAuth
Data category
Recording URLs, contact metadata
Region
US - Fireflies
Role
Transcript ingestion via customer connection
Data category
Customer-supplied transcript text
Region
US - Fathom
Role
Transcript ingestion via customer connection
Data category
Customer-supplied transcript text
Region
US
Communications
- SendGrid
Role
Transactional email delivery
Data category
Recipient email address, email body
Region
US - DocuSeal
Role
E-signature for onboarding agreements
Data category
Admin name, email, signed agreement
Region
US
Billing
- Stripe
Role
Subscription billing and payment processing
Data category
Billing contact, payment metadata (no card data on our servers)
Region
US
Supporting infrastructure providers (caching, bot protection, error monitoring) that do not receive call content are disclosed on the complete legal list. See all sub-processors
Documents on request
Everything security review needs
Data Processing Agreement
Signed DPA available on request for any paid customer — see /dpa for terms and request flow.
Security questionnaire response
CAIQ-aligned questionnaire response available under NDA.
Architecture and controls overview
Detailed control documentation covering data flow, encryption, access, and monitoring.
SOC 2 Type II report
Available to customers and prospects under NDA once issued; we will note issuance on this page.
Want the architectural depth?
Encryption, integration verification, prompt-injection defense, and the rest of the security architecture live on the Security page.
See security architectureProcurement FAQ
Procurement questions, answered
Mid-questionnaire? Send it over — we answer within one business day. security@closeintel.ai
Not yet. A SOC 2 Type II readiness program is in progress, targeting Q4 2026. Until the report is issued we share control documentation, our architecture overview, and a CAIQ-aligned security questionnaire response under NDA.
Yes. A DPA is available on request for any paid customer and covers GDPR, CCPA, and other US state privacy laws. The full terms and request flow are summarized at /dpa; email security@closeintel.ai or use the contact form below to receive the current executable version.
No. Our AI providers — Anthropic, OpenAI, and AssemblyAI — contractually exclude API data from model training under their commercial terms. We process your call content; we do not learn from it.
Primary tenant data runs in US regions on managed Postgres. Edge and bot-protection providers operate globally. The sub-processor table above lists the region for every service that processes your content; the complete legal list at /sub-processors covers supporting infrastructure providers as well.
Production access is least-privilege, MFA-enforced, and logged. Every privileged action is captured in an append-only audit log, and access is promptly revoked when someone leaves.
Email security@closeintel.ai. We typically respond within one business day, investigate every report, and credit researchers when a finding leads to a fix.
Trust, verified
Security review needed?
We provide a security questionnaire response, data processing agreement, and architecture overview on request — usually within one business day.