Security and subprocessors
What KPI Shield does with your call data, who else touches it, and what we never do.
Isolation between customers
Every customer's data lives in rows tagged with its organization. Postgres row-level security is forced on every customer table, and each request runs as a restricted database role pinned to one organization, so a missed filter returns nothing instead of another customer's data.
Credentials
Dialer API keys are encrypted (AES-256-GCM) before they are stored and are never shown again. Incoming webhooks are checked against a per-connection secret, and their content is never trusted: an event only brings the next sync forward.
Access and audit log
Roles decide who sees what: managers see their own teams, HR and admins see everything, and reps see only their own results through a signed link. Every finding view, evidence opening, decision, export and settings change is written to an audit log your admins can read.
What we keep, and for how long
We keep call records and the findings built from them, for the periods in your retention settings. Transcripts are fetched only for recorded calls of 60 seconds or more that a check selects (at most 40 per rep per week, including ordinary conversations) or that are already in an open finding. They are kept 30 days at most and then deleted. A transcript the AI labels as a personal call is deleted immediately. An uploaded call export is stored encrypted and deleted as soon as its import finishes. A legal hold keeps a case's data until it is released. We don't record calls or store audio.
Calls we never analyze
Calls to numbers on your protected list (HR, unions, legal, government agencies, hotlines) are left out of every check and never sent to an AI model. Reps can register personal numbers so those calls are excluded too.
AI use
AI labels are one input to a review by a person, never a decision. Names, emails, phone numbers and addresses are masked before a transcript is sent. The model first sees only about the first minute of a call; a call that is clearly personal stops there and its text is deleted. Calls go through Anthropic's standard Messages API, which is eligible for zero data retention. Anthropic's batch interface is not eligible, so it is off, and it would be turned on only after its retention terms were disclosed to you. A zero-data-retention arrangement with Anthropic, and Anthropic's written confirmation that this use is permitted, are not yet in place; until the arrangement is, Anthropic's standard API data retention applies.
Certifications
We have not completed a SOC 2 audit. Policies are being written now; we will publish the audit status here.
Subprocessors
| Company | What for | Where |
|---|---|---|
| Vercel | Application hosting and scheduled jobs | United States |
| Neon | Database (Postgres), including uploaded call exports, stored encrypted until they are deleted | United States |
| Anthropic | AI labels of selected calls and case summaries, on plans with AI review, through the standard Messages API. Zero data retention not yet in place: Anthropic's standard API data retention applies | United States |
| Resend | Email, when email is switched on: rep portal links, invitations and the weekly summary | United States |
This list changes only with notice to customers under the data processing agreement. Pilots are US-only: EU and UK customers are not onboarded yet. There is no separate file-storage provider.
Planned, not built
- Slack: Optional weekly summary posts, only if you connect it. Not built yet.
For your legal and HR teams
Customers can download a compliance pack in the app (notice templates, a risk-assessment worksheet, AI instructions for use and a model card). Drafts of our terms and data processing agreement are online and marked as drafts until counsel review is complete.
