This page summarizes our security program. For our full security package — SOC 2 report, penetration test summary, and questionnaire responses — contact security@contributeai.org.
Infrastructure & data protection
Encryption
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Voice and call data are encrypted end-to-end within Google Cloud.
Cloud platform
Hosted on Google Cloud (SOC 2, ISO 27001, HIPAA-eligible) — the infrastructure that powers Google Workspace for millions of businesses.
Data residency
Regional deployment options (US, EU) and private-cloud / VPC deployment available for enterprise customers.
Data minimization
Least-privilege OAuth scopes; call transcripts used only for intent detection and deleted after the session or per your retention policy.
Access & identity
- SSO / SAML with Okta, Azure AD, and Google Workspace.
- SCIM provisioning for automated user onboarding & de-provisioning.
- Role-based access control (RBAC) with least-privilege defaults.
- Immutable audit logs of every action, exportable to your SIEM.
- Internal access follows least-privilege, is logged, and requires MFA.
Compliance
- SOC 2 Type II — report available under NDA.
- ISO 27001 — information security management.
- GDPR & CCPA — DPA available; see request a DPA.
- HIPAA — HIPAA-eligible deployment with BAA for healthcare customers.
Reliability
We target 99.9% uptime with a contractual SLA for enterprise plans, 24/7 monitoring, redundant infrastructure, and a public status page.
Vulnerability management & responsible disclosure
We run regular third-party penetration tests and continuous vulnerability scanning. If you believe you've found a security issue, please email security@contributeai.org — we investigate all reports promptly and will not pursue action against good-faith research.