Security & Data
Built to keep each business and caller context separated.
Sonorch applies tenant isolation, scoped integrations, sanitized operational logging, and configurable data handling throughout the voice and scheduling workflow.
Current Safeguards
Security controls across the call lifecycle.
Tenant-scoped data
Business configuration, caller records, memories, call logs, and scheduling tools are resolved and queried within the owning tenant.
Caller-only memory input
Caller memory is derived from caller speech. Agent output is excluded before memory extraction and persistence.
Sanitized operational logs
Phone numbers, transcript content, secrets, and raw provider payloads are excluded from informational logs.
Verified webhooks
Inbound provider events are signature-verified before they can update call, billing, or routing state.
Scoped business actions
Scheduling actions use configured tenant tools and permissions rather than unrestricted access to a business system.
Retention and deletion controls
Tenant configuration includes data-retention settings, and tenant records can be permanently deleted with their related data.
Transparency
Security claims should be precise.
This page describes current product controls. It is not a claim of certification under a named compliance framework.
Businesses with specific regulatory, retention, integration, or vendor-review requirements should discuss them with Sonorch before enabling production call handling.
For a security or data-handling question, email contact@sonorch.ai or use the contact form.