How we protect your information
These are the technical and organisational measures we apply today. They match clause 7 of the Data Processing Agreement (in Spanish), where they are spelled out in full.
- Encryption in transit: communications travel over TLS/HTTPS (and the equivalents in telephony and streaming).
- Authentication and role-based access control with signed tokens: everyone reaches only what they should.
- Strict isolation between accounts (multi-tenant): a customer's data and cloned voices are reachable only from their own account.
- Two barriers for administrative functions: the role is checked in the token and revalidated against the database, deny-by-default, plus an audit log of administrative actions.
- Least privilege and confidentiality for authorised personnel.
- File upload validation and controls against unauthorised requests to internal resources.
- Monitoring and backups of the information.
We are transparent about the limits: as of today we hold no third-party certifications (SOC 2, ISO 27001) and have had no external security audits. We work continuously to preserve the confidentiality, integrity and availability of the information, and we accept reports under our Responsible Disclosure Policy (in Spanish).
Do you have specific security requirements for your company? Write to us.