Security

Your customers' conversations are the most sensitive thing we hold.

Our agents handle phone calls and text messages containing names, addresses, phone numbers and sometimes the state of somebody's home at midnight. Here is how that data is handled.

Tenant isolation
Each client's data is isolated at the database layer, not by a filter in application code. Conversations, contacts and knowledge bases are never pooled across businesses.
Encryption
All traffic is served over TLS. Data at rest is encrypted by our managed database and storage providers using industry-standard AES-256.
Access control
Access to production systems is limited to personnel who need it, authenticated individually, and logged. We do not use shared credentials.
Least-privilege integrations
When we connect to your calendar or CRM we request the narrowest scope that does the job. You can revoke our access from your side at any time.
Retention you control
Conversation transcripts and contact records are retained for as long as your agreement is active, or a shorter period you specify. On termination we delete or return your data on request.
Incident response
If we become aware of a breach affecting your data we will notify you without undue delay, with what we know, what we are doing, and what we need from you.
Subprocessors

Who else touches the data.

We use third-party infrastructure to run the service. This is the current list — we would rather publish it than have you discover it in a contract appendix.

ProviderPurposeProcessing region
TwilioVoice and SMS deliveryUnited States
NeonManaged Postgres databaseUnited States
RailwayApplication hostingUnited States
SentryError monitoringUnited States
LeadConnector / HighLevelChat widget and CRM workflowsUnited States
Large language model providersAgent reasoning and language generationUnited States
Being straight about our stage. We are a young company. We hold no SOC 2 or ISO 27001 certification today, and we are not going to imply otherwise — some vendors describe themselves as “enterprise-grade” and let you assume the rest. The controls above are real and in place. If your procurement process requires a formal attestation, tell us on the audit call and we will give you a straight answer about whether we are a fit yet.

Security questions? Email gage@getbedrockai.com or get in touch.

BEDROCK AI LLC, 4972 State Hwy 30, Huntsville, TX 77340, United States. Telephone (936) 355-8233.