Security & compliance

Call recordings are the most sensitive data you hold

They contain identity documents, payment details and medical context, spoken out loud. This page is the detail your security review will ask for, written before you have to ask for it.

Encrypted in transit and at rest · Stored in region

Agent configuration: recording, live transcript, manager approval, escalation to a person and language, each behind its own switch

The controls, in short

The detail

What a security review usually asks next.

Where your data lives

Data residency is set when the account is created and does not move afterwards. Indian customers are provisioned in the Mumbai region, and call audio, transcripts, derived scores and CRM mirrors all stay within it. Backups stay in the same region as the primary.

Sub-processors are listed in the data processing agreement, along with what each one receives. We notify customers before a sub-processor is added.

Regulatory posture

The platform is built against the following frameworks. Where a certification is in progress rather than complete, it is described that way here and on the footer badges — an in-progress SOC 2 is useful information, and claiming it as finished is not.

  • India's Digital Personal Data Protection Act — consent capture, purpose limitation, and deletion on request.
  • GDPR — for customers operating in the EU, with the standard contractual clauses in the DPA.
  • HIPAA — a BAA is available for healthcare customers on enterprise plans.
  • PCI DSS — payment details are redacted from recordings and transcripts rather than stored.
  • TRAI TSR and DLT — sender IDs and templates registered before any Indian SMS traffic runs.
  • SOC 2 Type II — in progress. We will publish the report when it is issued, and not before.

Access, and who has it

Access is role-based and scoped to a campaign. A team lead sees their own team's calls; an analyst sees aggregates without the audio unless that is granted explicitly. Every grant is logged.

Hyperdial staff do not have standing access to customer recordings. Support access is time-boxed, requires a named approver on your side, and appears in your audit log the same as any other access.

Recording announcements are configurable per region and per campaign, so a flow can meet a two-party consent requirement where one applies. Consent state travels with the contact record across channels.

  • Card numbers and CVVs are detected and redacted before the recording is written to storage.
  • Identity numbers can be redacted on the same basis, per campaign.
  • Redaction applies to the transcript as well as the audio — a redacted call is redacted everywhere.

Deleting a contact removes their recordings, transcripts, scores and CRM mirror. Deletion is a real deletion, not a hidden flag, and completes within the window stated in the DPA.

Availability and incidents

Paid plans carry a 99.9% uptime target, with the contractual terms set out in the order form. Live status is published at status.hyperdial.io.

Security incidents affecting your data are notified to your named contact within the window the DPA specifies, with what we know at the time rather than after the investigation closes.

Questions a security review always asks

Read the DPA →
Can we get the penetration test report?

Yes — the executive summary is available under NDA, and the full report to enterprise customers during procurement. Ask your account contact or write to us from the contact page.

Do you train models on our call data?

Not across customers. A playbook learned from your recordings is yours, is used only for your account, and is not pooled into a shared model that other customers benefit from.

Where exactly is Indian data stored?

In the Mumbai region, including backups. Residency is fixed at account creation and does not move without a written change.

Can we bring our own encryption keys?

Customer-managed keys are available on enterprise plans. Talk to us about your key management requirements before signing.

What happens to our data if we leave?

You can export recordings, transcripts and derived data at any time through the API or a scheduled export. On termination, data is deleted within the window set out in the DPA.

Send us your security questionnaire

SECURITY & COMPLIANCE
GDPR COMPLIANT
Encrypted in transit and at rest, stored in region