Home/Security
Security & data residency

Built to survive
your security review.

Most conversation intelligence is SaaS-only, which means your customer recordings leave your network and live on a vendor's infrastructure. For a lot of insurers, banks, and health systems that single fact ends the evaluation. Overtone was architected the other way round.

On-prem system of record No raw audio at rest off-network Zero training on your data
Deployment models

Three shapes. You pick
where the data lives.

Most regulated

On-premises

Your data center

Transcripts, scores, metrics, and the search index all persist in your SQL Server. Audio is streamed into memory from your recorder and discarded after transcription — never written to disk anywhere.

  • System of record never leaves your network
  • Outbound HTTPS only — no inbound path exists
  • Windows Integrated Auth or AD FS
  • Air-gapped variant with local inference
  • Runs on VMs or bare metal — no Kubernetes required

Private cloud

Your tenant

We ship containers and Terraform into your own Azure, AWS, or GCP subscription. You hold the keys, own the network, keep the logs, and pay the cloud bill directly.

  • Customer-managed encryption keys
  • Region pinning for residency requirements
  • Private endpoints, no public ingress
  • Every audit event streamed to your SIEM
  • You can revoke our access at any time

Managed SaaS

Our cloud

Single-tenant storage per customer in a US or EU region. Fastest path to value, and you can migrate to private cloud later without re-implementing.

  • Single-tenant storage, never pooled
  • AES-256 at rest, TLS 1.3 in transit
  • US or EU region election at contract
  • SSO via Entra ID, Okta, or Ping
  • Documented exit and data-return process
Data flow

Where audio goes,
and where it stops.

This is the diagram your security architect actually wants. In an on-premises deployment there are exactly three places data exists, and only one of them persists anything.

Never leaves

1 · Your recorder

Recordings stay in the source system. Overtone reads them over your own network via API, into memory, and releases the buffer the moment transcription returns. Nothing is copied to a staging store.

Transient only

2 · Inference

Speech and language models receive a call and return text. Nothing is retained, logged, cached, or used for training — enforced contractually with providers and verified by architecture tests in every release.

System of record

3 · Your database

Transcripts, scores, metrics, and the full-text index persist only in your SQL Server. Retention, backup, and destruction follow your policy, on your schedule, under your DBA's control.

Things Overtone never does

Negative guarantees are usually more useful in a security review than positive ones, so here are ours in plain language.

NeverWrite raw audio to disk outside your boundaryEnforced
NeverTrain shared models on your conversationsContractual
NeverOpen an inbound network path into your estateArchitectural
NeverPersist PII in the search indexPre-index redaction
NeverPool customer data in shared storageSingle tenant
NeverAccess your production data without a ticketBreak-glass, logged
Privacy

PII is removed before
anything is written down.

Redaction runs between transcription and persistence — not as a display filter afterwards. By the time a transcript reaches your database, the sensitive spans are already gone or tokenized.

  • Card numbers, CVV, and the whole PCI capture window
  • Government identifiers — SSN, SIN, NHS, national ID
  • Dates of birth, addresses, phone numbers, email addresses
  • Policy, member, claim, and account numbers
  • Protected health information under HIPAA
  • Custom patterns you define — internal codes, partner references

You choose per data class whether a masked span is recoverable by privileged role for dispute resolution, or irreversibly destroyed at capture. Most regulated customers destroy PCI data and tokenize everything else.

Redaction passPre-persistence
02:19Customer My policy is [POLICY_ID] and the card ends [PAN_LAST4], expiry [EXP].
02:31Agent Got it. And can you confirm your date of birth?
02:36Customer [DOB]
DetectedSensitive spans this call7
DestroyedPCI — irreversible3
TokenizedRecoverable by QA lead role4
IndexPII entering search index0
Compliance

Attestations and frameworks.

Reports, penetration test summaries, and our completed CAIQ are available under NDA. Ask your account team or write to security@alphadecibel.com.

Audited

SOC 2 Type II

Security, availability, and confidentiality. Annual audit with continuous control monitoring between cycles.

Certified

ISO/IEC 27001

Information security management system covering product, infrastructure, and corporate operations.

Aligned

HIPAA

BAA available. PHI masked before persistence; on-premises deployment keeps PHI entirely inside your covered entity.

Compliant

GDPR & UK GDPR

EU region election, standard contractual clauses, DPA, and documented subprocessor list with change notice.

Compliant

CCPA / CPRA

Consumer rights request handling, including deletion propagation into transcripts and the search index.

Scoped

PCI DSS

Card data destroyed at capture, so Overtone reduces rather than expands your cardholder data environment.

Supported

NAIC & state DOI

Disclosure, replacement, and suitability evidence packs for insurance regulators across 50 states.

In progress

FedRAMP Moderate

Pursuing authorization for public sector deployments. Target authorization in the next fiscal year.

Engineering practice

How we actually operate.

AreaPractice
EncryptionAES-256 at rest, TLS 1.3 in transit. Customer-managed keys on private cloud and on-premises.
Access controlLeast privilege, enforced MFA, quarterly access reviews. Production access is break-glass, ticketed, time-boxed, and logged.
NetworkOutbound-only from on-premises deployments. Private endpoints and no public ingress in private cloud.
SecretsHardware-backed key storage. No credentials in source, enforced by pre-commit and CI scanning.
SDLCMandatory peer review, SAST and dependency scanning on every pull request, signed builds, reproducible releases.
TestingAutomated architecture tests assert no audio write path and no cloud storage resource exists in on-prem builds.
Penetration testingIndependent third-party test annually plus after any material architecture change. Summary shared under NDA.
Vulnerability managementCritical patched within 7 days, high within 30. Continuous dependency monitoring with automated PRs.
MonitoringCentralized audit logging with tamper-evident storage. Customer-side events streamable to your SIEM.
Incident response24×7 on-call, documented runbooks, tabletop exercises twice yearly. Customer notification within 24 hours of confirmed incident.
Business continuityActive-passive DR with documented RPO of 15 minutes and RTO of 4 hours. Restore tested quarterly.
PersonnelBackground checks, annual security training, role-based training for engineers handling customer data.
SubprocessorsPublished list with 30 days' notice before any addition. On-premises deployments can run with none.

Responsible disclosure

If you believe you've found a vulnerability in Overtone or in our infrastructure, we want to hear about it before anyone else does. Write to security@alphadecibel.com. We acknowledge within one business day, keep you updated through remediation, and credit researchers who ask to be named.

Documentation available under NDA

SOC 2 Type II report ISO 27001 certificate Penetration test summary CAIQ / SIG Lite Architecture & data-flow diagrams DPA and subprocessor list BAA template BC/DR test results
Security review

Send us your
questionnaire.

We'd rather start with your security team than end with them. Send over your vendor assessment and we'll return it completed, with architecture diagrams, before the first commercial conversation.