Security & Compliance

Your data security is
our top priority.

Enterprise-grade security controls built into every layer of the platform. Designed for teams that handle sensitive call data.

AES-256 Encrypted
SOC 2 Infrastructure
Audit Logging
Data Retention Controls
Row-Level Security
TLS 1.3 in Transit

Security Controls

AES-256-GCM Encryption

Active

All call transcripts are encrypted at the application level using AES-256-GCM before storage. Even if the database is compromised, transcript data is unreadable without the encryption key.

Comprehensive Audit Logging

Active

Every access to sensitive data — transcripts, reports, and meetings — is logged with user identity, timestamp, IP address, and action type. Required for HIPAA compliance auditing.

Configurable Data Retention

Active

Administrators can set automatic data retention policies (30, 60, 90, 180, or 365 days). Transcripts are automatically purged after the retention period expires.

Session Security

Active

Configurable session timeout policies enforce automatic logout after periods of inactivity. Administrators can set timeouts from 30 minutes to 8 hours.

Infrastructure Security

Active

Built on SOC 2 Type II certified infrastructure. Database hosted on Supabase (SOC 2, ISO 27001). Application hosted on Vercel (SOC 2). All data encrypted in transit via TLS 1.3.

Row-Level Security

Active

Every database table enforces row-level security policies ensuring complete data isolation between organizations. Users can only access data within their own organization.

Error Monitoring

Active

Real-time error tracking and crash reporting via Sentry ensures issues are detected and resolved quickly, maintaining platform reliability and data integrity.

Role-Based Access Control

Active

Three-tier role system (User, Admin, Superadmin) with server-side enforcement. All actions are verified against the user's role before execution.

Infrastructure Partners

We build on certified, enterprise-grade infrastructure from trusted cloud providers.

Supabase

Database & Authentication

SOC 2 Type IIISO 27001HIPAA (with BAA)

Vercel

Application Hosting & CDN

SOC 2 Type IIGDPR

OpenAI

AI Analysis Engine

SOC 2 Type IIGDPRAPI BAA Available

Sentry

Error Monitoring

SOC 2 Type IIGDPR

Questions about security?

We take security seriously. If you have specific compliance requirements or questions about our security practices, we are happy to discuss them.

© 2026 Kalyxi Inc. All rights reserved.

Back to Home