Trust Centre

Evidence, not assurances.

Voice calls carry names, addresses, account numbers and medical details. This page tells you where that data lives, who can reach it, how long we keep it, and what we can prove about what happened on any single call.

▪ SOC 2 Type II, renewed 3 March 2026 ▪ Four regions, four DPAs ▪ Sub-processor list versioned at 12
At a glance
Certifications
8 current, 0 in remediation
Residency
UK, EU, US, India, UAE, Australia
Audio retention
180 days default, 7 days to 7 years configurable
Encryption
TLS 1.3 in transit, per-workspace keys at rest
Key management
Customer-managed keys on Sovereign
Incident page
Under 15 minutes, 24 hours a day
Certifications and attestations

Eight things an auditor has actually checked.

Reports are shared under NDA through the audit pack, usually within one business day. We do not publish redacted certificates as a substitute for the report.

ICO registeredRegistration ZB739214, data protection fee paid
Cyber Essentials PlusUK government scheme, renewed annually
SOC 2 Type II12-month window to Feb 2026, zero exceptions
ISO 27001Certified since Nov 2024, surveillance audit passed
UK GDPR & DPA 2018UK and EU residency, IDTA and DPA signed
HIPAABAA available for covered entities and BAs
India DPDPIn-country processing, consent artefacts per call
PCI DSS SAQ-ACard data is never spoken, never captured
PECR · TPS & CTPSConsent and suppression enforced before dialling
WCAG 2.2 AAConsole and Studio audited, VPAT on request
What is not certified. Our model providers are sub-processors, not certified extensions of Nivākya. Where a deployment routes inference through a third-party model, that flow is listed in the sub-processor table with its region, and Sovereign workspaces can substitute a customer-hosted model instead.

Data residency

Where your calls physically live.

Residency is set per workspace, enforced at the storage layer rather than by policy statement, and changed only with a signed instruction from an owner. Support access follows the same pinning.

RegionWhere it runsAudioTranscriptsSupport accessDefault retention
United States uk-south-1 and us-west-2, active-active Encrypted object storage, per-workspace key Encrypted Postgres, same region US-based staff only 180 days audio · 24 months transcripts
European Union Frankfurt and Amsterdam EU-only buckets, EU-only keys EU-only cluster EU-resident staff only 90 days audio · 24 months transcripts
United Kingdom London, with EU failover disabled by default UK-only buckets UK-only cluster UK or EU staff only 90 days audio · 24 months transcripts
India Mumbai primary, Hyderabad DR In-country buckets, DPDP scoped In-country cluster India-based staff only 90 days audio · 24 months transcripts
United Arab Emirates Dubai, in-country partner facility In-country, regulated-sector default In-country cluster UAE-based staff only 60 days audio · 12 months transcripts
Australia Sydney AU-only buckets AU-only cluster AU or APAC staff only 180 days audio · 24 months transcripts
Retention is a setting, not a default you inherit. Audio can be as short as 7 days or as long as 7 years. Legal hold overrides the deletion clock for a specified case and is logged with the requesting user, the reason and the expiry date.
Deletion is verifiable. When a workspace deletes a recording, the object is removed from storage, the key is retired, and the deletion event is written to the audit log with the object hash so you can prove what was removed and when.
Security architecture

Six layers, each one able to fail without taking the others down.

LAYER 01 — IDENTITY

Least privilege, proven daily

SAML SSO and SCIM provisioning for customers; hardware security keys required for every Nivākya employee. Production access is just-in-time, time-boxed to four hours, and reviewed by a second engineer who is not on call.

LAYER 02 — NETWORK EDGE

Media terminates at the carrier

Signalling runs over TLS 1.3 and media over SRTP. The runtime accepts no inbound connections from the public internet — the only path in is a pre-authenticated carrier trunk pinned to a workspace's region.

LAYER 03 — RUNTIME ISOLATION

A cell per workspace

Each workspace runs in its own cell with dedicated compute, its own in-memory policy cache and its own key material. No tenant shares process memory, threads or a filesystem with another tenant, even inside one region.

LAYER 04 — DATA PROTECTION

Redaction before persistence

Card digits, government identifiers, addresses and dates of birth are redacted in the streaming pipeline, before a transcript row is written. Envelope encryption uses a per-workspace data key, rotatable on request.

LAYER 05 — APPLICATION INTEGRITY

Signed agents, fail-closed policy

Every published agent version is signed by a rehearsal pass. The policy engine fails closed: if a rule cannot be evaluated, the agent escalates to a human rather than improvising a shortcut.

LAYER 06 — VISIBILITY

Fifteen minutes to a page

Every region carries 24/7 on-call with a 15-minute page target, an immutable event stream and a quarterly tabletop exercise. Incident reviews are published to affected workspace owners within 72 hours.


Audit and logging

A hash for every turn, queryable the same day.

Compliance teams usually ask the same question: can you show me what the agent said, what it was allowed to say, and whether either was altered afterwards. The audit log is built to answer that without opening a support ticket.

Capture, at the turn

Each conversational turn takes the previous turn's hash, the current speech act, the policy decision and the tool results, and produces a new SHA-256 digest. The chain is per call.

Redact, before storage

Identifiers are stripped in the pipeline. The redaction map is stored separately under a different key, and only roles with the PII-view scope can rejoin the two.

Persist, region-pinned

Transcripts and hashes land in the workspace region only. There is no cross-region replication of conversation data, not even for analytics.

Query, through one interface

The audit API answers by call ID, caller number, policy clause, agent version or date range, and returns the chain plus a verification verdict per turn.

Sample audit query
Query
policy_clause = “P-114 disclosure” AND region = “eu-central”, last 30 days
Result
18,204 turns across 2,117 calls
Chain verdict
2,117 / 2,117 intact
Redactions
31,880 identifiers removed
Denied actions
14 tool calls blocked by policy, all escalated
Export
Signed CSV or JSON bundle, hash manifest included

The same interface is exposed in the Console under Intelligence → Audit, and over the API. Every export is itself logged.

Legal documents

Eight documents, summary first.

Nobody reads the whole policy before a demo, so here is what each document actually commits us to. The full text is available in the audit pack or from your account team.

PRIVACY POLICY · V9 · 14 AUG 2026 Privacy policy

Nivākya is a processor for conversation data and a controller only for account and billing records. We collect the minimum needed to run a call, we do not sell or share data with advertisers, and we do not use customer conversations to train shared models. Data-subject requests received through a customer are answered within seven days, and requests that arrive directly are routed to the customer rather than answered unilaterally.

TERMS OF SERVICE · V6 · 14 AUG 2026 Terms of service

The agreement covers the platform, the console, the API and the agent library, and it sets the SLA by plan tier. Customers remain responsible for the lawfulness of the calls they place, including consent and do-not-call compliance in the jurisdiction they are dialling. Liability is capped at twelve months of fees, except for data-protection breaches and indemnity claims, where the cap is twice that. Termination for convenience requires 30 days' notice and exports are available for 60 days afterwards.

COOKIE POLICY · V4 · 02 JUN 2026 Cookie policy

The marketing site sets one strictly necessary session cookie and nothing else until you accept analytics. The Console requires a session cookie and a CSRF token; it may not be operated without them. We run no advertising pixels, no cross-site trackers and no third-party analytics on authenticated pages, which is why there is no consent banner inside the product.

DATA PROCESSING ADDENDUM · V7 · 14 AUG 2026 Data processing addendum

The DPA incorporates the EU Standard Contractual Clauses, the UK International Data Transfer Addendum and, for India, the DPDP processing terms. It fixes the processing purpose to “providing the voice-agent service”, prohibits any secondary use, and defines breach notification at 24 hours from confirmation. Sub-processor changes carry 30 days' notice with a right to object, and the addendum names the region of every transfer rather than relying on a general adequacy statement.

SUB-PROCESSOR REGISTER · V12 · 01 SEP 2026 Sub-processors

Twelve sub-processors are engaged across compute, storage, telephony, payments, email and observability. Each is bound by contract to terms no weaker than our own DPA, each is reviewed annually, and each is listed with the purpose it serves and the region it operates in. Adding a sub-processor starts a 30-day notice clock for every customer, and any customer may object and receive a workaround or a termination right. The full table is below.

ACCESSIBILITY · VPAT 2.5 · 19 MAY 2026 Accessibility

The Console and Studio were audited against WCAG 2.2 Level AA by an external firm and are currently conformant apart from two documented partial-support items in the live transcript viewer, both listed in the VPAT with dates. Keyboard operation is complete, the live transcript announces turns through an ARIA live region, and colour is never the only signal. A public accessibility contact answers reports within two business days.

RESPONSIBLE AI · V3 · 24 JUL 2026 Responsible AI

Agents must disclose that they are automated when asked, must never impersonate a specific real person, and must hand over to a human on the specific triggers a customer declares. Emotion inference is off by default and cannot be enabled for healthcare or lending deployments. We publish the fabrication rate of our models quarterly and treat any upward trend as a release blocker, not a footnote.

SECURITY DISCLOSURE · V2 · 11 FEB 2026 Security disclosure

Researchers may test any Nivākya-owned surface except live customer workspaces and carrier infrastructure. We acknowledge reports within one business day, triage critical findings within 24 hours, and will not pursue legal action for good-faith research that stays inside that scope. Verified findings are credited in the release notes unless the reporter prefers otherwise, and we publish the count of resolved reports each quarter.

Sub-processor register · version 12

Twelve companies that touch your data.

Every one of them is named, scoped and regionalised. Where a sub-processor handles audio, it sees it only in transit unless the table says otherwise.

Sub-processorPurposeRegionData it can see
Helios ComputeStreaming ASR and inferenceUS, EU, APACAudio in transit, no persistence
Vantage Object StorageRecording and export storageMatching workspace regionEncrypted audio and bundles
Northgate Carrier ServicesTelephony termination and number portingUS, EU, APACCaller and called numbers, metadata
Brightline AnalyticsDerived reporting warehouseEU, USTranscripts, metadata, scores
Cobalt MailTransactional and notification emailUSAccount emails only
Meridian ObservabilityLogging, metrics and tracingUS, EURedacted events, no audio
Sunder Transcription QAHuman quality sampling, opt-inIndiaRedacted transcripts only
Aurora PaymentsPayment links and settlementEU, USNo call data, tokenised references

Four further sub-processors cover internal engineering tooling and carry no customer data; they are listed in register version 12 alongside the eight above. Objections go to the privacy contact through the demo form and are answered within five business days.

Start

Get the audit pack, then ask us the hard question.

The pack contains the SOC 2 report, the ISO certificate, the signed DPA, the current VPAT and the sub-processor register. It arrives under NDA, usually the same day.

Security questions to security@ — answered by the engineers who own the systems, not by a form.