Data and security

Your calls stay yours

FluentlySaid practices sit on your most sensitive material: real call recordings, transcripts, and internal playbooks. Here is exactly how we handle it.

GDPR compliant

DPA available on request

SOC 2 Type II

audit in progress

No training on your data

generation only, never fine-tuning

Your data is never used to train a model

We use pre-trained models to generate scenarios and score calls. That is all they do. Your recordings, transcripts, playbooks and documents are never fed back into training or fine-tuning, ours or any model vendor's. The people who reviewed your last call are an AI reading a transcript, not a model learning from your deals.

  • Pre-trained models, used for output generation only
  • No fine-tuning, no model refinement, on any customer content
  • Contractual no-training terms with the model providers we use

Retention on your terms

Different teams need different things. Some want a full history to track a rep's climb over a quarter, others want the shortest window their policy allows. We set a retention window with you, tighten it per requirement, and run scheduled purges so nothing lingers past its date. You can delete a session, a rep's history, or your whole workspace at any time.

  • Retention window agreed with you, not a fixed default
  • Scheduled purges and regular data-hygiene reviews
  • Self-serve deletion for a session, a user, or the workspace

Infrastructure and uptime

The platform runs on a major cloud provider with encryption in transit and at rest, network isolation, and access logging. Redundancy and failover are built in so a single fault does not take the service down. We target 99.9% availability and treat any drop as an incident.

  • Encryption in transit and at rest
  • Network controls, firewalls and intrusion detection
  • Redundancy and failover, 99.9% availability target

Authentication and access

Getting into an account should be easy for the right person and hard for everyone else. Admins manage their own users without filing a ticket. Two-factor authentication is available on every account, and SSO lets your team sign in through the identity provider you already trust. Internally, staff access to customer data is least-privilege and logged.

  • Self-serve user management for admins
  • Two-factor authentication on every account
  • SSO through your identity provider (team and enterprise plans)
  • Least-privilege, logged internal access

Compliance

We are GDPR compliant today and can sign a Data Processing Agreement. Our SOC 2 Type II audit is in progress, and we are happy to walk your security team through our controls and answer a vendor questionnaire in the meantime.

  • GDPR compliant, DPA available
  • SOC 2 Type II audit in progress
  • Security questionnaires and review calls welcome

Reviewing us as a vendor?

Send your security questionnaire, ask for the DPA, or book time with us to go through the controls. We move fast on this.