Talkwisely is built on Amazon Web Services with encryption at rest and in transit, role-based access control, region-locked data storage, and contractual guarantees that your data is never used to train AI models.
AES-256
Encryption at Rest
TLS 1.2+
Encryption in Transit
72 hrs
Breach Notification SLA
ISO 27001
Certification Roadmap
Every one of these measures is live today — not aspirational.
All personal data stored on our servers is encrypted using AES-256. This includes call recordings, transcripts, account data, and AI-generated outputs.
All data between your device and our infrastructure is encrypted using TLS 1.2 or higher. There are no unencrypted channels.
Access to personal data is restricted by role. Only authorised personnel with a documented business need may access specific data sets.
MFA is mandatory for all Talkwisely staff who access systems containing customer data. No single-factor access to production systems.
Every access to customer data is logged with a timestamped audit trail. Logs are retained and available for security reviews.
We run continuous intrusion detection systems across our AWS infrastructure to identify and respond to anomalous activity in real time.
Network-level DDoS protection is active across all public endpoints, with automatic traffic scrubbing to maintain service availability.
We conduct regular penetration testing of the Talkwisely platform, both scheduled and ad-hoc, performed by independent security researchers.
Continuous static and dynamic analysis (SAST/DAST) is run across our codebase and infrastructure. Security patches are applied promptly.
Background checks are conducted for all employees and contractors who have access to systems containing customer data, prior to access being granted.
Talkwisely runs on AWS. Region-locked storage is available on all plans — no upsell required. EU data never leaves the EU. Indian data never leaves India.
EU/EEA customer data is stored in EU AWS regions and never transferred outside the EU/EEA. Standard Contractual Clauses (SCCs) govern any onward transfers required for AI API calls.
Indian customer data is stored in AWS India regions and not transferred outside India. Processing complies with India's DPDP Act 2023 and IT Act 2000.
UK customer data is stored in AWS UK regions. Processing complies with UK GDPR.
All other customers may designate their preferred AWS region at account creation. We support regions across North America, Asia-Pacific, Europe, and the Middle East.
Talkwisely uses third-party AI APIs to power analytics features. Every provider is bound by a DPA that contractually prohibits using customer data to train, fine-tune, or improve AI models. This guarantee is written into our customer DPA.
AI Providers & Guarantees
Anthropic (Claude)
Call summaries, conversational analytics, agent coaching
Commercial API DPA — no training on customer data
Google (Gemini API)
Analytics and natural language processing
Google Cloud DPA — model improvement disabled by default
OpenAI
Analytics features
API Data Processing Addendum — training disabled by default
xAI (Grok)
Analytics features
Enterprise DPA — no training on customer data
Deepgram
Speech-to-text transcription
DPA — no model training on customer audio
AssemblyAI
Speech-to-text and audio intelligence
DPA — no model training on customer audio
Security, privacy and compliance are fundamental to how we build and operate Talkwisely. Our security programme is aligned with recognised industry standards, with independent certifications forming part of our long-term commitment to continuous improvement.
We are implementing an Information Security Management System (ISMS) aligned with ISO 27001:2022, with independent certification planned as part of our ongoing security programme.
Our security controls are designed in line with the SOC 2 Trust Services Criteria. Independent Type I attestation forms part of our compliance roadmap following ISO 27001.
Following SOC 2 Type I, we intend to pursue Type II attestation to demonstrate the ongoing operational effectiveness of our security controls.
We support customers operating in healthcare and healthcare-adjacent industries. Business Associate Agreements (BAAs) are available where appropriate.
Payment card processing is handled exclusively by our PCI DSS compliant payment partners, Stripe (PCI DSS Level 1) and Razorpay. Talkwisely does not store, process or transmit full payment card numbers.
We provide a GDPR-compliant Data Processing Agreement (DPA) to customers upon request. A self-service DPA will be made available through our Trust Centre.
Enterprise teams can request our Data Processing Agreement, SCC documentation, or a security briefing. We respond within one business day.