Data minimization
The model sees only what the task needs. Sensitive fields are masked or redacted before they reach a prompt, and transcripts are trimmed to what operations require.
Security & Compliance
AI systems handle calls, documents, and records that carry real risk. Every DPI deployment starts with the data map, the access model, and the escalation rules, and stays reviewable after launch.
Principles
The model sees only what the task needs. Sensitive fields are masked or redacted before they reach a prompt, and transcripts are trimmed to what operations require.
Role-based access to consoles, transcripts, and documents, single sign-on where available, least privilege for service accounts, and secrets kept out of code.
Every automated action, hand-off, and human override is logged with who, what, when, and why, so reviews and regulators get answers instead of guesses.
Defined thresholds send uncertain or high-impact cases to a person with full context. The AI never becomes the last line of decision for something that matters.
Hosted models under enterprise terms, AWS Bedrock inside your AWS account, or fully self-hosted open-source models where residency or cost demand it.
Healthcare
For clinics, practices, and healthcare operations teams we sign a Business Associate Agreement before protected health information is involved. Architectures are designed to HIPAA requirements: encrypted transport and storage, access logging, minimum-necessary data in prompts, private or BAA-covered model hosting, and retention rules for recordings and transcripts.
Typical healthcare workloads include patient intake and scheduling by phone, prior authorization paperwork, referral processing, and documentation support. See the industries overview for the operational side.
Voice
Voice agents run on an Asterisk-based core that connects to your existing IP telephony over SIP, so calls stay on your numbers and carriers. Recording and transcription follow state consent rules, with announcements where the law requires them. Outbound campaigns are built for TCPA compliance: consent records, calling windows, opt-out handling, and do-not-call checks before a call is placed.
Speech-to-text and text-to-speech can run on open-source models inside your environment, which keeps audio off third-party services when that matters. Details on the AI voice agent development page.
Infrastructure
| Layer | Options | When we recommend it |
|---|---|---|
| Language models | OpenAI, Anthropic Claude, AWS Bedrock, self-hosted Qwen and other open-source models | Hosted for capability and speed; Bedrock inside your AWS account; self-hosted for residency, cost per minute, or regulation |
| Speech | Open-source STT and TTS models, hosted speech APIs | Self-hosted for healthcare and finance; hosted where latency budgets allow and data is not sensitive |
| Data | PostgreSQL, pgvector, Qdrant, Redis | In your cloud account or ours, encrypted, with retention rules per data type |
| Runtime | Docker, Kubernetes, AWS, Cloudflare | Same stack in every environment, with CI pipelines on GitLab or GitHub and rollback on every release |
Security Review
IT and compliance teams are part of every discovery. We walk through the data flow diagram, the access model, logging, incident response, and vendor terms, and we adjust the architecture before a line of code is written. Contact us to start with your security questionnaire.
FAQ
No. Hosted providers are used under enterprise terms that exclude training on your data, and self-hosted models run entirely inside your environment. Prompts, transcripts, and documents stay yours.
Yes. Open-source language models such as Qwen and open-source speech models can run on your infrastructure, with the telephony core on Asterisk and data in your own PostgreSQL, Qdrant, or Redis instances.
Yes, for any workload that touches protected health information. The BAA is signed before discovery involves patient data, and the architecture is designed to HIPAA requirements from the start.
Recording and transcription follow the consent rules of the states involved, with announcements where required. Recordings and transcripts are stored with access controls and retention limits you set, and can be excluded entirely.
We design and operate to SOC 2 style controls (access, change management, monitoring, incident response) and can share our practices in a security review. Ask about formal audit status during discovery.
Next Step
Tell us where calls, tickets, documents, or approvals pile up. We map the workflow, size the impact, and propose a deployment you can measure.