Trust & Security
Last updated: 24 July 2026
How we protect your data and your callers’ data, in plain language. This page is written to be shared: send it to your security reviewer along with our DPA.
1. Architecture and tenant isolation
Each client gets an isolated workspace in our portal. Data separation is enforced at the database layer with Supabase row-level security policies, not just in application code, so one client can never query another’s calls, transcripts or leads. PLACEHOLDER: confirm RLS coverage on all tables before publishing.
2. Encryption
- In transit: TLS on all connections between callers, our systems and providers.
- At rest: databases and file storage (recordings) are encrypted at rest by our infrastructure providers (Supabase/AWS).
3. Access control
- Client portal access is authenticated (Supabase Auth) and scoped to your workspace and role.
- Internal access to production data is limited to authorised AiAnchor personnel on a least-privilege basis, for support and operations. PLACEHOLDER: confirm MFA enforcement and the current access list process.
4. System integrity
- Webhooks between telephony, automation and the portal are signature-verified so events can’t be forged. PLACEHOLDER: confirm implementation status.
- Administrative actions and data access are logged. PLACEHOLDER: confirm audit-log scope.
- Backups: PLACEHOLDER: document backup schedule and restore testing.
5. Where data lives
Portal data is hosted on Supabase (PLACEHOLDER: confirm project region; EU regions such as Frankfurt are available and preferred). Call processing runs on Retell AI (AWS, USA) under EU Standard Contractual Clauses. This website is served by Vercel. Full detail per provider is in the subprocessor table below.
6. Subprocessor transparency
The complete list of companies that touch service data, why, and under which terms:
7. Compliance posture
- GDPR: we sign a DPA with every client that needs one; SCCs cover non-EEA transfers.
- EU AI Act: our agents disclose AI interaction in-call; see the AI Disclosure Policy.
- Our vendors hold SOC 2 attestations (Retell: Type I & II; Supabase: Type II). AiAnchor itself does not yet hold its own certification; we say so honestly rather than implying otherwise.
8. Reporting a vulnerability
If you believe you have found a security issue in our website, portal or agents, email info@aianchor.online with the subject “Security report”. We acknowledge within 2 business days, keep you informed, and do not pursue good-faith researchers. Please do not access other clients’ data or disrupt the service while testing. PLACEHOLDER: dedicated security@ address once created.
9. DPA and documentation requests
Security questionnaires, DPA signing and subprocessor notifications: info@aianchor.online. We aim to turn questionnaires around within PLACEHOLDER: confirm (e.g. 5 business days).