Infrastructure security
- Unique production database authentication enforced
- Encryption key access restricted
- Unique account authentication enforced
Telephos is an AI-powered platform that processes call recordings, transcripts, and team communications like Slack messages to deliver actionable business insights and optimize workflows. Security is core to everything we build. Our SOC 2 audit is complete, covering Security, Availability, and Confidentiality with encryption at rest and in transit, role-based access control, continuous vulnerability monitoring, and rigorous vendor management.
Telephos uses Anthropic's API (Claude) for portions of analysis (call transcript reasoning and complex business-insight extraction). Per Anthropic's standard API terms, content submitted via the API is not used to train Anthropic's models. Excerpts of transcript text and derived prompts are sent; no PII beyond what appears in call content. Processed in US regions. Learn more at anthropic.com.
Telephos uses OpenAI's API for portions of analysis (transcript classification and summarization). Per OpenAI's standard API terms, content submitted via the API is not used to train OpenAI's models. Excerpts of transcript text and derived prompts are sent; no PII beyond what appears in call content. Processed in US regions. Learn more at openai.com.
Managed application hosting and PostgreSQL database infrastructure. Processes call transcript text, customer account metadata, user identifiers, and integration tokens. Data resides in Render-managed infrastructure in the United States. Selected for SOC 2 Type II audited controls, managed Postgres with at-rest encryption, and private networking between services. Learn more at render.com.
Hosts Telephos's frontend web applications (marketing site, customer web app). Processes in-flight web requests including authenticated session data. No persistent storage of customer data on Vercel; persistent data resides in Render-managed infrastructure. Processed in US regions.
Yes. All customer data is encrypted at rest using AES-256 encryption via our managed PostgreSQL database. Data is also encrypted in transit using TLS 1.2+ for all API and web traffic. Sensitive fields like API credentials are additionally encrypted at the application layer using AES-256-GCM before storage.
Telephos infrastructure is hosted on Render, a SOC 2-certified cloud platform built on AWS and GCP. All production services and databases run in US-based data centers. We have no on-premises servers. We are fully cloud-native.