Skip to content
Trueline

Security and compliance

Nothing is recorded, so nothing can leak.

Trueline scores a call while it is happening and keeps the score, not the call. Audio is held in memory for the length of one scoring window and then discarded, on our infrastructure or inside your own network.

Audio at rest
None, on any deployment
Longest any audio is held
Eight seconds, in memory
Transcripts
None. The model scores sound, not words
Retention of scores
Thirty days by default, down to zero

0

Bytes of audio written to disk

On our infrastructure or yours. Audio is scored in memory and discarded.

8s

Maximum time any audio exists

One scoring window and its overlap, then it is gone. Not a policy, a buffer size.

0

Transcripts, voiceprints or enrolments

Nothing is made that could identify a caller later, so there is nothing to leak.

What exists, and for how long

Audio for eight seconds. Scores for as long as you say.

The only thing that outlives the call is a list of numbers: one score per window, with the rule and the engine release that produced it.

Caller audio
Discarded from memory
Scores
Transcript
none, ever: the model scores sound, not words
0s10s20s30s
what exists at any moment during a call, and what is left after it

scores kept 30 days by default, or 0 · erased on request

Controls

Built in, not bolted on.

Where it runs

Ours or yours, the same eight seconds.

Nothing in Trueline depends on a particular cloud, so the box that runs in your network is the hosted service with your keys.

Hosted by us

One URL. Audio is scored in our memory and is gone within eight seconds.

Your network
Trueline cloud

Hosted in your network

The same build in your VPC or on premises. Licence key only, no call-home.

Your network
Trueline box

a copy of the audio, over TLS 1.2+, held in memory ≤ 8 sa flag, and nothing else, back to your systems

The questionnaire

Every control, and whether it is live.

What is on the roadmap is marked as such. A reviewer finds out either way.

  • Audio at restLive

    None. Audio exists in memory for at most eight seconds per call and is never written to disk or object storage.

  • TranscriptionLive

    None, ever. The model scores acoustics; no words are produced or kept.

  • Tenant isolationLive

    The tenant is taken from the API key on every query. Isolation is covered by tests that try to cross it.

  • API keysLive

    Hashed at rest, shown once, identifiable by prefix. Two can be active per tenant, so rotation has an overlap.

  • Session tokensLive

    Single use, valid for sixty seconds, issued per call.

  • WebhooksLive

    Signed over timestamp and body, five-minute replay window, retried on a schedule with every attempt visible. Secrets rotate with an overlap.

  • Platform credentialsLive

    Encrypted per tenant with AES-256-GCM and bound to their row. Revoking erases them. Every use is written to an append-only audit log.

  • Audit trailLive

    Every state change on a call records the engine release, the rule in force, the window and the time.

  • Retention and erasureLive

    Scores and metadata are kept thirty days by default, configurable down to zero. A call can be erased on request and later reads say so.

  • TransportLive

    TLS 1.2 or later only.

  • IP allow-list and mTLSRoadmap

    Per tenant, on request.

  • Data residencyRoadmap

    Regional cells for the US and the EU. Today, customer-hosted deployment keeps audio in your network.

  • SOC 2Roadmap

    Trueline's own attestation is on the roadmap. We do not hold one today.

Compliance

The paperwork, stated plainly.

Send us the questionnaire before the pilot, not after.

Most of it is answered on this page. The rest is shared under NDA during scoping.