Security & Data

Built to keep each business and caller context separated.

Sonorch applies tenant isolation, scoped integrations, sanitized operational logging, and configurable data handling throughout the voice and scheduling workflow.

Current Safeguards

Security controls across the call lifecycle.

Tenant-scoped data

Business configuration, caller records, memories, call logs, and scheduling tools are resolved and queried within the owning tenant.

Caller-only memory input

Caller memory is derived from caller speech. Agent output is excluded before memory extraction and persistence.

Sanitized operational logs

Phone numbers, transcript content, secrets, and raw provider payloads are excluded from informational logs.

Verified webhooks

Inbound provider events are signature-verified before they can update call, billing, or routing state.

Scoped business actions

Scheduling actions use configured tenant tools and permissions rather than unrestricted access to a business system.

Retention and deletion controls

Tenant configuration includes data-retention settings, and tenant records can be permanently deleted with their related data.

Transparency

Security claims should be precise.

This page describes current product controls. It is not a claim of certification under a named compliance framework.

Businesses with specific regulatory, retention, integration, or vendor-review requirements should discuss them with Sonorch before enabling production call handling.

For a security or data-handling question, email contact@sonorch.ai or use the contact form.