Trust is part of the architecture.
How we think about security and privacy, what we build in by default, and what depends on your deployment. No certifications are claimed on this page; where we are in any assessment, we'll tell you directly.
Principles we build to.
These apply to every deployment. Specific controls are confirmed per customer.
Secure API authentication
Per-environment keys sent as bearer tokens, revocable at any time. Keys are never embedded in client-side code.
Least-privilege access
Agents can call only the tools attached to them, with only the permissions granted. People get the narrowest role that does their job.
Encryption in transit
All traffic between browsers, telephony providers, our services and your systems uses TLS.
Secure secret management
Credentials for your systems are stored in a managed secret store and referenced by name, never copied into agent configuration.
Access controls
Role-based access to configuration, transcripts and logs, with an audit trail of who changed what.
Data minimization
Agents collect only the fields a workflow needs. Public demos use synthetic data and store nothing.
Retention policies
Transcripts, recordings and summaries are retained for the period you configure, then deleted. Defaults favour shorter retention.
Logging and monitoring
Tool calls, escalations and configuration changes are logged. Logs avoid storing sensitive content where it isn't needed.
Human oversight
Sensitive actions can require approval. Escalation rules are part of every agent, and transcripts are reviewable.
Third-party providers
Speech, language-model and telephony providers process data as part of a deployment. We document which providers are involved and under what terms.
Privacy-aware AI design
Agents answer from approved sources, decline out-of-scope requests, and are configured to say clearly when they cannot help.
What depends on your deployment
Security and regulatory obligations depend on the deployment, the data processed, the customer, and the applicable jurisdiction. Recording consent, identity verification, data residency and retention are configured with you, not assumed.
Healthcare and other regulated data
For healthcare use cases we avoid storing patient information until appropriate controls, contractual arrangements and compliance requirements have been assessed. Public demonstrations are administrative only and use synthetic data.
We do not claim SOC 2, ISO 27001, HIPAA, GDPR or any other certification or compliance status on this site. If a status is verified in future, it will be stated here with its scope and date.
Reporting a security concern
If you believe you've found a vulnerability in this website or our services, email contact@samvaadagents.com with the subject "Security report". Please don't include customer data in the report. We'll acknowledge receipt and keep you informed.
Have a security questionnaire?
Send it over. We'd rather answer specific questions precisely than make general claims.