Evidence, not assurances.
Voice calls carry names, addresses, account numbers and medical details. This page tells you where that data lives, who can reach it, how long we keep it, and what we can prove about what happened on any single call.
- Certifications
- 8 current, 0 in remediation
- Residency
- UK, EU, US, India, UAE, Australia
- Audio retention
- 180 days default, 7 days to 7 years configurable
- Encryption
- TLS 1.3 in transit, per-workspace keys at rest
- Key management
- Customer-managed keys on Sovereign
- Incident page
- Under 15 minutes, 24 hours a day
Eight things an auditor has actually checked.
Reports are shared under NDA through the audit pack, usually within one business day. We do not publish redacted certificates as a substitute for the report.
Where your calls physically live.
Residency is set per workspace, enforced at the storage layer rather than by policy statement, and changed only with a signed instruction from an owner. Support access follows the same pinning.
| Region | Where it runs | Audio | Transcripts | Support access | Default retention |
|---|---|---|---|---|---|
| United States | uk-south-1 and us-west-2, active-active | Encrypted object storage, per-workspace key | Encrypted Postgres, same region | US-based staff only | 180 days audio · 24 months transcripts |
| European Union | Frankfurt and Amsterdam | EU-only buckets, EU-only keys | EU-only cluster | EU-resident staff only | 90 days audio · 24 months transcripts |
| United Kingdom | London, with EU failover disabled by default | UK-only buckets | UK-only cluster | UK or EU staff only | 90 days audio · 24 months transcripts |
| India | Mumbai primary, Hyderabad DR | In-country buckets, DPDP scoped | In-country cluster | India-based staff only | 90 days audio · 24 months transcripts |
| United Arab Emirates | Dubai, in-country partner facility | In-country, regulated-sector default | In-country cluster | UAE-based staff only | 60 days audio · 12 months transcripts |
| Australia | Sydney | AU-only buckets | AU-only cluster | AU or APAC staff only | 180 days audio · 24 months transcripts |
Six layers, each one able to fail without taking the others down.
Least privilege, proven daily
SAML SSO and SCIM provisioning for customers; hardware security keys required for every Nivākya employee. Production access is just-in-time, time-boxed to four hours, and reviewed by a second engineer who is not on call.
Media terminates at the carrier
Signalling runs over TLS 1.3 and media over SRTP. The runtime accepts no inbound connections from the public internet — the only path in is a pre-authenticated carrier trunk pinned to a workspace's region.
A cell per workspace
Each workspace runs in its own cell with dedicated compute, its own in-memory policy cache and its own key material. No tenant shares process memory, threads or a filesystem with another tenant, even inside one region.
Redaction before persistence
Card digits, government identifiers, addresses and dates of birth are redacted in the streaming pipeline, before a transcript row is written. Envelope encryption uses a per-workspace data key, rotatable on request.
Signed agents, fail-closed policy
Every published agent version is signed by a rehearsal pass. The policy engine fails closed: if a rule cannot be evaluated, the agent escalates to a human rather than improvising a shortcut.
Fifteen minutes to a page
Every region carries 24/7 on-call with a 15-minute page target, an immutable event stream and a quarterly tabletop exercise. Incident reviews are published to affected workspace owners within 72 hours.
A hash for every turn, queryable the same day.
Compliance teams usually ask the same question: can you show me what the agent said, what it was allowed to say, and whether either was altered afterwards. The audit log is built to answer that without opening a support ticket.
Capture, at the turn
Each conversational turn takes the previous turn's hash, the current speech act, the policy decision and the tool results, and produces a new SHA-256 digest. The chain is per call.
Redact, before storage
Identifiers are stripped in the pipeline. The redaction map is stored separately under a different key, and only roles with the PII-view scope can rejoin the two.
Persist, region-pinned
Transcripts and hashes land in the workspace region only. There is no cross-region replication of conversation data, not even for analytics.
Query, through one interface
The audit API answers by call ID, caller number, policy clause, agent version or date range, and returns the chain plus a verification verdict per turn.
- Query
- policy_clause = “P-114 disclosure” AND region = “eu-central”, last 30 days
- Result
- 18,204 turns across 2,117 calls
- Chain verdict
- 2,117 / 2,117 intact
- Redactions
- 31,880 identifiers removed
- Denied actions
- 14 tool calls blocked by policy, all escalated
- Export
- Signed CSV or JSON bundle, hash manifest included
The same interface is exposed in the Console under Intelligence → Audit, and over the API. Every export is itself logged.
Eight documents, summary first.
Nobody reads the whole policy before a demo, so here is what each document actually commits us to. The full text is available in the audit pack or from your account team.
Nivākya is a processor for conversation data and a controller only for account and billing records. We collect the minimum needed to run a call, we do not sell or share data with advertisers, and we do not use customer conversations to train shared models. Data-subject requests received through a customer are answered within seven days, and requests that arrive directly are routed to the customer rather than answered unilaterally.
The agreement covers the platform, the console, the API and the agent library, and it sets the SLA by plan tier. Customers remain responsible for the lawfulness of the calls they place, including consent and do-not-call compliance in the jurisdiction they are dialling. Liability is capped at twelve months of fees, except for data-protection breaches and indemnity claims, where the cap is twice that. Termination for convenience requires 30 days' notice and exports are available for 60 days afterwards.
The marketing site sets one strictly necessary session cookie and nothing else until you accept analytics. The Console requires a session cookie and a CSRF token; it may not be operated without them. We run no advertising pixels, no cross-site trackers and no third-party analytics on authenticated pages, which is why there is no consent banner inside the product.
The DPA incorporates the EU Standard Contractual Clauses, the UK International Data Transfer Addendum and, for India, the DPDP processing terms. It fixes the processing purpose to “providing the voice-agent service”, prohibits any secondary use, and defines breach notification at 24 hours from confirmation. Sub-processor changes carry 30 days' notice with a right to object, and the addendum names the region of every transfer rather than relying on a general adequacy statement.
Twelve sub-processors are engaged across compute, storage, telephony, payments, email and observability. Each is bound by contract to terms no weaker than our own DPA, each is reviewed annually, and each is listed with the purpose it serves and the region it operates in. Adding a sub-processor starts a 30-day notice clock for every customer, and any customer may object and receive a workaround or a termination right. The full table is below.
The Console and Studio were audited against WCAG 2.2 Level AA by an external firm and are currently conformant apart from two documented partial-support items in the live transcript viewer, both listed in the VPAT with dates. Keyboard operation is complete, the live transcript announces turns through an ARIA live region, and colour is never the only signal. A public accessibility contact answers reports within two business days.
Agents must disclose that they are automated when asked, must never impersonate a specific real person, and must hand over to a human on the specific triggers a customer declares. Emotion inference is off by default and cannot be enabled for healthcare or lending deployments. We publish the fabrication rate of our models quarterly and treat any upward trend as a release blocker, not a footnote.
Researchers may test any Nivākya-owned surface except live customer workspaces and carrier infrastructure. We acknowledge reports within one business day, triage critical findings within 24 hours, and will not pursue legal action for good-faith research that stays inside that scope. Verified findings are credited in the release notes unless the reporter prefers otherwise, and we publish the count of resolved reports each quarter.
Twelve companies that touch your data.
Every one of them is named, scoped and regionalised. Where a sub-processor handles audio, it sees it only in transit unless the table says otherwise.
| Sub-processor | Purpose | Region | Data it can see |
|---|---|---|---|
| Helios Compute | Streaming ASR and inference | US, EU, APAC | Audio in transit, no persistence |
| Vantage Object Storage | Recording and export storage | Matching workspace region | Encrypted audio and bundles |
| Northgate Carrier Services | Telephony termination and number porting | US, EU, APAC | Caller and called numbers, metadata |
| Brightline Analytics | Derived reporting warehouse | EU, US | Transcripts, metadata, scores |
| Cobalt Mail | Transactional and notification email | US | Account emails only |
| Meridian Observability | Logging, metrics and tracing | US, EU | Redacted events, no audio |
| Sunder Transcription QA | Human quality sampling, opt-in | India | Redacted transcripts only |
| Aurora Payments | Payment links and settlement | EU, US | No call data, tokenised references |
Four further sub-processors cover internal engineering tooling and carry no customer data; they are listed in register version 12 alongside the eight above. Objections go to the privacy contact through the demo form and are answered within five business days.
Get the audit pack, then ask us the hard question.
The pack contains the SOC 2 report, the ISO certificate, the signed DPA, the current VPAT and the sub-processor register. It arrives under NDA, usually the same day.
Security questions to security@ — answered by the engineers who own the systems, not by a form.