FAQ
Do you encrypt data at rest?
Yes. All customer data is encrypted at rest using AES-256 encryption via our managed PostgreSQL database. Data is also encrypted in transit using TLS 1.2+ for all API and web traffic. Sensitive fields like API credentials are additionally encrypted at the application layer using AES-256-GCM before storage.
Where are your servers located?
Telephos infrastructure is hosted on Render, a SOC 2-certified cloud platform built on AWS and GCP. All production services and databases run in US-based data centers. We have no on-premises servers. We are fully cloud-native.
How do you monitor for security breaches?
Our infrastructure provider includes built-in intrusion detection and DDoS protection. We run automated vulnerability scanning via GitHub Dependabot, maintain a documented incident response plan tested annually, and conduct quarterly access reviews. All security events are logged.
How can I report a security vulnerability?
Please report security vulnerabilities responsibly to security@telephos.ai. We acknowledge all reports within 24 hours and work with reporters to address validated issues promptly. We have a responsible disclosure policy and do not take legal action against good-faith security researchers.
Who has access to customer data?
Access to customer data follows the principle of least privilege. Only authorized personnel with a documented business need can access production systems. All access requests require Security Officer approval, are logged, and reviewed quarterly. Employees sign confidentiality agreements and multi-factor authentication is required for all production systems.
What compliance certifications does Telephos hold?
Telephos has completed its SOC 2 audit, covering Security, Availability, and Confidentiality.
What is your data retention policy?
Customer data is retained for the duration of the service agreement plus a defined wind-down period. Data processing results, transcripts, and analytics are stored in encrypted databases with role-based access controls. Customers can request data deletion at any time by contacting security@telephos.ai, and upon account termination, customer data is permanently deleted within 30 days. We do not retain customer data beyond what is necessary to provide the service. Backup data follows the same retention and deletion schedules.
How do you handle incident response?
Telephos maintains a documented incident response plan that is tested annually through tabletop exercises. Our plan covers detection, containment, eradication, recovery, and post-incident review. Security incidents are classified by severity, with defined escalation procedures and response timelines. We notify affected customers within 72 hours of confirming a data breach, as required by our privacy policy and applicable regulations.
Do you perform regular security assessments?
Yes. We conduct quarterly access reviews across all systems, annual risk assessments covering 10 threat scenarios, and continuous vulnerability scanning via GitHub Dependabot. Our infrastructure provider (Render) undergoes independent SOC 2 audits. We also perform annual tabletop exercises for both disaster recovery and incident response to validate our preparedness.
How do you ensure business continuity?
Telephos runs entirely on cloud infrastructure with no on-premises dependencies. Our services are deployed on Render with automated failover and redundancy. We maintain a documented disaster recovery plan that is tested annually through tabletop exercises. Database backups are automated and encrypted. Our recovery time objective (RTO) and recovery point objective (RPO) are defined and regularly validated.
How is access to production systems controlled?
Production system access follows the principle of least privilege. Only authorized personnel with a documented business need can access production infrastructure. All access requests require approval from the Security Officer or CEO and are logged. We use role-based access control, enforce multi-factor authentication on all systems, and conduct quarterly access reviews to verify permissions remain appropriate.
Do you train AI models on customer data?
No. Telephos uses third-party LLM provider APIs (Anthropic, OpenAI). Per these providers' standard API terms, content submitted via the API is not used to train their models. Customer data is processed only to provide analysis features and is never used by Telephos to train any model.
Do you offer a Data Processing Agreement (DPA)?
Yes. Our standard Data Processing Agreement is available at telephos.ai/trust under Resources, and we will sign customer-supplied DPAs upon request. Our DPA includes the current list of subprocessors and EU Standard Contractual Clauses (SCCs) where applicable.
How are subprocessor changes communicated to customers?
New subprocessors and material changes are published at telephos.ai/trust/subprocessors. Customers may object to material subprocessor changes per the terms of our DPA. Contact security@telephos.ai with questions.
How do customers request deletion of their data?
Customers may request deletion of their data at any time by emailing security@telephos.ai. Deletion is processed within 30 days of request and includes removal from production systems and primary backups, subject to retention obligations in our terms (e.g., legal hold). A deletion confirmation is provided upon completion.
Is data encrypted in transit?
Yes. All connections to Telephos services use TLS 1.2 or higher. API traffic, web traffic, and inter-service communication within our infrastructure are all encrypted in transit. Encryption at rest is also applied to all customer data in our database and object storage.
Are customer data backups encrypted?
Yes. Our managed PostgreSQL provider (Render) encrypts all backups at rest using industry-standard encryption. Backups are retained per our recovery objectives and are accessible only through audited restore workflows.