Security & trust

HiloVoice speaks directly with your customers, so how we handle data matters. Here's how it works today.

How HiloVoice handles data

Your organization's agent configurations, contacts, call records, and outcomes are scoped to your organization and never shared across organizations.

Encryption

Data is encrypted in transit (TLS) and at rest.

Tenant isolation

Every request is scoped to your organization. HiloVoice's services are designed so a request cannot reach another organization's data, even if an identifier is supplied incorrectly.

Credentials and secrets

API keys and integration credentials are stored in an encrypted credential store — never in agent definitions, call transcripts, or logs.

Call recordings

Audio retention is configurable. You control whether call recordings are stored, and for how long.

Transcript retention

Transcript retention is configurable per organization, so you can align storage with your own data policies.

Access controls

Roles — Owner, Admin, Builder, Analyst — control what each team member can see and do inside your organization.

Agent permissions

Each agent is limited to the specific information and actions you approve — nothing more.

Human escalation

Agents can be configured to transfer or escalate a conversation to a person whenever the workflow calls for it.

Auditability

Key actions — publishing an agent, launching a campaign, changing a configuration — are recorded so you can see who did what, and when.

Provider subprocessors

HiloVoice's initial voice runtime and telephony are provided by third-party infrastructure. We'll keep this page updated as our subprocessor list changes.

Compliance controls

Outbound calling includes configurable do-not-call handling, opt-out tracking, and calling-window restrictions by jurisdiction.

Responsible outbound calling

We don't assume a technically callable number is a legally callable one. Campaign controls exist to help you respect consent, calling windows, and opt-outs.

HiloVoice does not currently hold third-party security certifications. We'll publish them here if and when they're obtained.

Have a security question? Contact us.