Trust

1.

We do not use client production data to train models. Client systems use provider business/API services configured according to the provider's data-use controls; consumer chat interfaces are not used to process client production data.

2.

We request the minimum access needed.

3.

Read-only access is used first where possible.

4.

Client-owned accounts are used where practical.

5.

Credentials are not embedded in public code or casually shared.

6.

Documentation and configuration are handed over.

7.

Limitations — SOC 2, HIPAA/BAA, insurance status and other compliance constraints — are stated truthfully.

On "Zero Data Retention"

We do not claim Zero Data Retention (ZDR) as a blanket guarantee. ZDR is a separate, configuration-specific control offered by some providers for eligible accounts and endpoints — it is different from a provider's default "not used to train models" policy. Where ZDR genuinely applies to your specific build, we'll say so and confirm it against the actual provider, account, and endpoint in use — not before.

On retrieval-augmented (RAG) systems

Original files remain in the client's source system. Where retrieval requires an external index, approved text chunks and/or embeddings may be stored in the configured retrieval service. The provider, region, and retention policy are disclosed before deployment.

Subprocessors we use

Depending on what's being built, a system may run on some combination of: Vapi and Twilio (voice/telephony), OpenAI and Groq (language models), n8n, Make, or Zapier (workflow automation), Supabase (database/auth), Stripe (payments), and Resend (transactional email). We disclose the specific subprocessors used in your build before deployment, not after.

Retention

We keep only what's needed to operate and support the system — call/event logs and configuration, not unnecessary copies of client production data. Retention periods follow each subprocessor's own policy unless we agree to something stricter for your build.

Access controls

We request the minimum access a build needs, prefer read-only where a build allows it, and use client-owned accounts where practical rather than our own. Credentials are never embedded in public code or shared casually.

Continuity

Systems are documented well enough that another competent developer could take over. If a live system (like a voice agent) fails, calls fall back to your existing setup rather than disappearing.

Paperwork

We are not currently SOC 2 certified, do not currently sign HIPAA Business Associate Agreements, and do not take on medical/health data work at this stage. If your project has a specific compliance requirement, ask us directly and we'll tell you honestly whether we're the right fit.

Incident handling

If something breaks or behaves unexpectedly, we'll tell you directly and promptly, along with what happened and what we're doing about it. Reach us any time at info@stravolith.com.