Asisly
Security & Trust

Built so you can hand it to your lawyer.

Asisly protects every call, transcript, and customer record with the same care a regulated bank takes with deposits. Here's exactly how — in plain English — and where we are on the road to SOC 2 Type II.

Encryption everywhere

TLS 1.2+ in flight; AES-256 at rest. Recordings, transcripts, and customer rows are encrypted on the database and on every backup blob.

Two-factor on every admin

RFC 6238 TOTP required to access the admin console. Email allow-list scoped per customer; non-listed staff can't see your data even if they try.

Tamper-evident audit log

Every privileged action (team change, voice swap, data export, billing change) is logged with actor, IP, time, and metadata. Read-only and one-click exportable to CSV for your auditor.

Daily encrypted backups

pg_dump streams to an S3-compatible bucket every 24 hours. 30-day retention. RPO ≤ 24h, RTO ≤ 4h. Quarterly restore drills.

Tenant isolation

Row-level security enforced at the database. Every query runs scoped to a single business id. Zero shared service keys client-side.

Vulnerability response

Sentry on every server + browser path. Slack-paged on incident. We respond to security reports at [email protected] within one business day.

Sub-processors

Who we share your data with

Asisly is built on a small list of vetted infrastructure providers. Every one of them signs a DPA with us, and we'll happily sign one with you.

ProviderPurposeRegionDPA
SupabasePostgres, auth, file storageUS (EU on request)Yes
RailwayApplication hostingUS-West / EU-WestYes
VapiRealtime voice AI orchestrationUSYes
AnthropicConversational LLM (Claude)USYes
OpenAIStandard voice synthesisUSYes
ElevenLabsPremium / cloned voice synthesisUSYes
TwilioPhone numbers, SMS, voicemailGlobalYes
StripeSubscriptions + Connect payoutsUS / EUYes
ResendTransactional emailUSYes
Backblaze B2Encrypted backup storageUS-WestYes
SentryError trackingUS (EU on request)Yes
Compliance roadmap

Where we are

✓ Live today
  • • GDPR / CCPA-aligned data handling (DSAR within 30 days)
  • • Encryption in flight and at rest
  • • 2FA on admin console
  • • Audit log on every privileged action
  • • Daily encrypted backups
  • • Sub-processor list with DPAs
  • • Customer DPA available on request
  • • HIPAA BAA available for Pro / Scale plans
→ In progress
  • • SOC 2 Type I (target Q3 2026)
  • • SOC 2 Type II (target Q1 2027)
  • • Annual third-party penetration test
  • • ISO 27001 (post-SOC 2)

Got more questions?

We send our DPA, BAA, security questionnaire, or a redacted incident response runbook on request. Reply within one business day.

Email [email protected] Or talk to a human →