Skip to content
Trust center

Security, consent and brand safety.

How Outcraft AI protects your data, makes sure every call and message has permission, and keeps the AI agent speaking the way your brand would.

  • SOC 2 · in progress
  • HIPAA · in progress
  • GDPR · DPA with Standard Contractual Clauses
  • EU AI Act · assessed as not high-risk
  • Hosting · AWS Frankfurt, EU
  • TLS 1.3

    or higher for all data in transit

  • AES-256

    encryption for all stored data, keys in AWS KMS

  • 24 h

    to tell a customer about a personal-data breach

  • 7 days

    to apply a critical security patch

Security

Built to keep customer data safe.

The same measures we sign up to in our Data Processing Agreement, in plain words.

  • Encrypted everywhere

    All customer data is encrypted in transit and at rest. Names, emails and phone numbers get a second layer of encryption inside the application.

  • Hosted in the EU

    The platform runs on AWS in Frankfurt (eu-central-1), spread over several availability zones, deployed as code in isolated containers.

  • Closed network

    Private VPC, databases never exposed to the internet, Cloudflare DDoS protection, a web application firewall for the OWASP Top 10, and rate limits.

  • Strict access

    MFA for every team member, role-based access on least privilege, access reviewed every quarter and removed the day someone leaves.

  • Watched around the clock

    Continuous monitoring with real-time alerts and anomaly detection. Access and security logs are kept for at least 6 months.

  • Tested and patched

    Automated dependency and container scanning, a penetration test at least once a year, critical patches within 7 days, high-severity within 30.

  • A plan for incidents

    A written incident response plan: detect, contain, find the root cause, tell the people affected, and review what we learned.

  • Backed up daily

    Encrypted daily backups in the same AWS region, kept for 90 days, with restores and disaster recovery tested regularly.

Your data

Your data stays yours.

We do not use customer data - call recordings, transcripts or contact details - to train our AI models or those of our providers, unless you agree in writing. Our contracts with AI providers, OpenAI included, forbid it.

Customer data is hosted in the EU. When a provider outside the EU/EEA needs to handle it, the transfer is covered by Standard Contractual Clauses, as set out in the DPA.

  1. Any timeDelete customer data yourself in the app, or ask support.
  2. Within 30 days of leavingAsk for your data back as CSV or JSON.
  3. 30 days after the endData is removed from production systems.
  4. 90 days after the endData is gone from the last backup too.
Consent

Outcraft AI calls and messages people for our customers, so permission is a rule of the platform, not a setting. Customers agree to it in our Anti-spam Policy and Terms, including the rules of TCPA, CAN-SPAM, GDPR, the ePrivacy Directive and national Do Not Call registries.

  • Permission first

    Every AI call, SMS and email needs the person’s express, prior consent (or another lawful basis) for that type of message.

  • No bought or scraped lists

    No harvested contacts, no pre-checked consent boxes, and lists older than 12 months must be reconfirmed before use.

  • Easy to say stop

    A clear opt-out in every channel: reply STOP to an SMS, one click to unsubscribe from email, a spoken way out on a call.

  • Stop means stop

    Opt-outs and “do not call” requests are honoured at once. Opted-out and dead contacts are suppressed by the platform automatically.

Complaint limits we enforce

Above these rates a customer gets a warning. Higher rates mean the account is throttled, locked or closed.

  • Spam complaints0.1%
  • Bounces and failed deliveries4%
  • Unsubscribes2%
  • SMS opt-outs3%
  • Calls ending in “do not call again”5%
Brand safety

An agent that sounds like you, and says it is an AI.

You decide what the agent says. You can hear every call afterwards. And a person can take over when needed.

Live call · 00:02

“Hello, this is [Name], an AI assistant from [Your Company].”

  • It says it is an AI

    Our terms require the agent to introduce itself as an AI assistant to people in the EU, as the EU AI Act asks.

  • Your script, your voice

    You set the agent’s script, answers and behaviour, and you can change them at any time.

  • Calls you can replay

    Calls can be recorded and transcribed, so your team can review what the agent said and correct it.

  • A human is one step away

    Set up human hand-off and offer email or human support for people who would rather not talk to an AI.

  • We check too

    Our team may review contact lists, call scripts and voice-agent prompts, and watches carrier and email blacklists.

  • Not training data

    Your recordings, transcripts and contacts never train our models or our providers’ models (OpenAI included) without your written consent.

Documents

The full text, in writing.

Need a security review?

Above 10,000 leads a month, custom plans add a security review, custom terms and a named solutions engineer.