Security & Compliance

Security and Compliance for Production AI

AI systems handle calls, documents, and records that carry real risk. Every DPI deployment starts with the data map, the access model, and the escalation rules, and stays reviewable after launch.

Principles

Five commitments in every architecture

Data minimization

The model sees only what the task needs. Sensitive fields are masked or redacted before they reach a prompt, and transcripts are trimmed to what operations require.

Access control

Role-based access to consoles, transcripts, and documents, single sign-on where available, least privilege for service accounts, and secrets kept out of code.

Audit trails

Every automated action, hand-off, and human override is logged with who, what, when, and why, so reviews and regulators get answers instead of guesses.

Human escalation

Defined thresholds send uncertain or high-impact cases to a person with full context. The AI never becomes the last line of decision for something that matters.

Hosting choice

Hosted models under enterprise terms, AWS Bedrock inside your AWS account, or fully self-hosted open-source models where residency or cost demand it.

Healthcare

HIPAA-aligned deployments with a signed BAA

For clinics, practices, and healthcare operations teams we sign a Business Associate Agreement before protected health information is involved. Architectures are designed to HIPAA requirements: encrypted transport and storage, access logging, minimum-necessary data in prompts, private or BAA-covered model hosting, and retention rules for recordings and transcripts.

Typical healthcare workloads include patient intake and scheduling by phone, prior authorization paperwork, referral processing, and documentation support. See the industries overview for the operational side.

Voice

Telephony, recording, and consent

Voice agents run on an Asterisk-based core that connects to your existing IP telephony over SIP, so calls stay on your numbers and carriers. Recording and transcription follow state consent rules, with announcements where the law requires them. Outbound campaigns are built for TCPA compliance: consent records, calling windows, opt-out handling, and do-not-call checks before a call is placed.

Speech-to-text and text-to-speech can run on open-source models inside your environment, which keeps audio off third-party services when that matters. Details on the AI voice agent development page.

Infrastructure

What runs where

LayerOptionsWhen we recommend it
Language modelsOpenAI, Anthropic Claude, AWS Bedrock, self-hosted Qwen and other open-source modelsHosted for capability and speed; Bedrock inside your AWS account; self-hosted for residency, cost per minute, or regulation
SpeechOpen-source STT and TTS models, hosted speech APIsSelf-hosted for healthcare and finance; hosted where latency budgets allow and data is not sensitive
DataPostgreSQL, pgvector, Qdrant, RedisIn your cloud account or ours, encrypted, with retention rules per data type
RuntimeDocker, Kubernetes, AWS, CloudflareSame stack in every environment, with CI pipelines on GitLab or GitHub and rollback on every release

Security Review

Bring your questionnaire

IT and compliance teams are part of every discovery. We walk through the data flow diagram, the access model, logging, incident response, and vendor terms, and we adjust the architecture before a line of code is written. Contact us to start with your security questionnaire.

FAQ

Security questions we hear most

Will our data be used to train models?

No. Hosted providers are used under enterprise terms that exclude training on your data, and self-hosted models run entirely inside your environment. Prompts, transcripts, and documents stay yours.

Can the whole system run inside our own cloud or data center?

Yes. Open-source language models such as Qwen and open-source speech models can run on your infrastructure, with the telephony core on Asterisk and data in your own PostgreSQL, Qdrant, or Redis instances.

Do you sign a Business Associate Agreement?

Yes, for any workload that touches protected health information. The BAA is signed before discovery involves patient data, and the architecture is designed to HIPAA requirements from the start.

How are voice calls recorded and stored?

Recording and transcription follow the consent rules of the states involved, with announcements where required. Recordings and transcripts are stored with access controls and retention limits you set, and can be excluded entirely.

Are you SOC 2 certified?

We design and operate to SOC 2 style controls (access, change management, monitoring, incident response) and can share our practices in a security review. Ask about formal audit status during discovery.

Next Step

Bring one workflow. Leave with a production plan.

Tell us where calls, tickets, documents, or approvals pile up. We map the workflow, size the impact, and propose a deployment you can measure.