Security

Last updated: July 10, 2026

1. Our Commitment to Security

At SOVREN AI, security is foundational to everything we build. As a voice-first executive AI platform handling sensitive business communications, we maintain rigorous security standards to protect your data, your customers' data, and your business operations.

We employ a defense-in-depth strategy with multiple layers of protection across our infrastructure, application, and operational processes. We describe controls as they operate in production today, and we expand coverage continuously.

2. Infrastructure Security

2.1 Data Center Security

Our infrastructure is hosted in SOC 2 Type II certified data centers with physical security controls including biometric access, 24/7 surveillance, and environmental monitoring.

2.2 Network Security

  • Private VLAN isolation between all service components
  • Network segmentation with strict firewall rules
  • DDoS protection via Cloudflare
  • All external traffic encrypted with TLS 1.3
  • Internal service-to-service communication over private networks

2.3 GPU Infrastructure

AI inference workloads run on dedicated GPU nodes isolated from public-facing services, ensuring compute resources are protected from external access.

3. Application Security

3.1 Authentication & Authorization

  • JWT-based authentication with short-lived access tokens
  • Secure refresh token rotation
  • Row-Level Security (RLS) enforced at the database layer
  • Role-based access controls for multi-tenant isolation
  • Bcrypt password hashing with appropriate work factors

3.2 Data Protection

  • Encryption at rest for core identity and account data, with encryption coverage expanding across remaining product surfaces
  • Encryption in transit using TLS for all communications
  • Tenant data isolation at the database level
  • Secure credential storage with encryption
  • Documented retention and deletion procedures for account data (see Data Deletion)

3.3 Voice Pipeline Security

Voice communications traverse TLS-protected pipelines on isolated infrastructure. Where call recordings or transcripts are retained for a given configuration, they are stored in access-controlled systems; encryption-at-rest coverage for call content is expanding. We do not create voice clones or biometric templates from subscriber call audio.

4. Immutable Audit Trail

Significant actions within the SOVREN AI platform are recorded in append-only audit records designed to resist silent alteration. This includes:

  • Authentication events (login, logout, token refresh)
  • Configuration changes to AI executives
  • Voice call initiation, routing, and completion
  • Data access and modification events
  • Administrative actions and permission changes

Audit records support governance and incident review. Account deletion produces a sealed deletion receipt for covered stores; self-service export of the full audit history is not currently offered as a general product feature.

5. Operational Security

5.1 Monitoring & Incident Response

  • 24/7 infrastructure monitoring with automated alerting
  • Real-time metrics collection via Prometheus and Grafana
  • Automated anomaly detection on all service endpoints
  • Documented incident response procedures
  • Post-incident review process for continuous improvement

5.2 Access Controls

  • Principle of least privilege for all system access
  • SSH key-based authentication for infrastructure access
  • No shared credentials or default passwords
  • Regular access reviews and credential rotation

6. Compliance & Standards

SOVREN AI is designed to support common privacy and communications obligations:

  • TCPA-oriented controls for voice and SMS communications
  • GDPR-aligned data handling practices (access, correction, deletion request paths)
  • CCPA-aligned consumer rights support for California residents
  • PCI DSS scope for card payments handled by Stripe (card data does not rest on SOVREN systems)
  • Ongoing internal security review and third-party assessments as scheduled

7. Vulnerability Disclosure

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly:

  • Email: security@sovrenai.io
  • Include a detailed description of the vulnerability
  • Provide steps to reproduce the issue
  • Allow reasonable time for us to address the issue before public disclosure

We commit to acknowledging receipt within 24 hours and providing an initial assessment within 72 hours.

8. Contact

For security-related inquiries or concerns, please contact our security team:

SOVREN AI Security Team

Email: security@sovrenai.io

Website: https://sovrenai.io