Security & Trust
Last updated: 2026-07-16
Last updated: 16 July 2026
We build the AI Fortis Voice AI Platform to be secure by design.
- Encryption in transit: all traffic uses TLS (HTTPS).
- Encryption at rest: provider keys, SIP and integration secrets are encrypted with AES-256-GCM; databases and recording storage are encrypted at rest by our hosting providers.
- Tenant isolation: every record is scoped to its client and enforced with row-level security (RLS) in the database; application queries are additionally tenant-scoped.
- Access control: role-based access, optional multi-factor authentication (TOTP), and least-privilege service access.
- EU data residency: the primary application database (Supabase) is hosted in the EU; call recordings are stored in our own storage (Cloudflare R2).
- Recording disclosure: AI and recording disclosures are configured by the client in each agent's greeting and script.
- Data lifecycle: data is deleted on account closure and on verified erasure requests; website demo data is purged automatically.
- Monitoring: error and job-failure logging, usage and budget alerts, and service-health checks.
Note on certification: GDPR has no single official "certificate". We operate to GDPR requirements and can support audits; formal certifications (e.g. ISO 27001, SOC 2, or an accredited GDPR scheme) require a separate external audit, which we can pursue on request.
Security contact: office@aifortis.com.