Ssylo
Log inHear it live

Security & trust

Customer calls are sensitive. We treat them that way.

What Sylo handles is the most trusted line in your business. Below: exactly what we do with that data, how we handle third-party processors, where we are on independent audits, and what we haven’t earned yet.

SOC 2 Type IPlanned · pre-launch

We're working toward SOC 2 readiness; a Type I report is targeted before public launch.

SOC 2 Type IIPlanned · post-launch

Type II requires an observation period; it starts once a Type I report lands.

Penetration testPlanned · pre-launch

We intend to commission an independent third-party test of auth, payments, tenant isolation, and webhook security before general availability.

Encryption

In transit and at rest.

Customer data is encrypted in transit (TLS 1.3) and at rest in our database. Voice recordings and transcripts inherit the same posture as the rest of your data.

  • TLS 1.3 for all client + server traffic
  • At-rest encryption on database, file storage, and backups
  • Secrets in a dedicated store; no plaintext in source or logs
Tenant isolation

Your data, your tenant. By design.

Every row of data carries a tenant identifier. Row-level security in the database enforces that boundary on every read and write, not optionally at the application layer.

  • Row-level security policies on every public table
  • A second tenant-scope check in the AI retrieval layer: your data is re-verified as yours before any model sees it
  • No cross-tenant learning: your knowledge base never trains another tenant's AI
Identity & access

Multi-factor available. Least-privilege by default.

Any account can turn on multi-factor authentication, with recovery codes for a lost device. Wayhow staff reach tenant data only through a privileged internal credential, used only when you ask us to look into something.

  • MFA (authenticator app) available on every account, with recovery codes
  • No “log in as you” impersonation: staff access is via an internal credential, on request
  • Least-privilege access to production systems
Observability without leakage

Logs carry outcomes, not conversations.

Our monitoring captures errors, latencies, and call metadata, never the contents of customer conversations. LLM calls are logged metadata-only; prompts and completions are never sent to telemetry.

  • Conversation content lives in your dashboard, never in logs or error tracking
  • A redaction filter drops known-sensitive fields before logs leave our systems
  • LLM prompt and completion text is stripped from error reports
Recording consent

Compliant with your state's rules.

Sylo detects the caller's state from area code and applies the right disclosure script (one-party or two-party consent) for that jurisdiction. Disclosures are logged per call.

  • State-aware recording-consent script
  • EU/GDPR consent script for international callers
  • Audit log of every disclosure played
Your data is yours

Export it or delete it, any time.

From your dashboard you can export everything Sylo holds for your business as a single file, or permanently delete your account and all of its data, no support ticket required.

  • One-click data export (right to access / portability)
  • Self-serve account deletion (right to erasure) with full cascade
  • 30-day data availability window after cancellation

What we haven’t earned yet, and won’t claim.

We don’t have a SOC 2 Type II report yet. We don’t have HIPAA certification; Healthcare is a separately gated tier we haven’t activated. We don’t claim ISO 27001 or HITRUST. Anyone in this category is either being honest about a pre-launch posture or stretching. We’d rather miss a quarter than ship a claim we can’t back.

If you need any of the above contractually today, we’re not the right fit yet, and we’ll say so on the discovery call. Talk to us anyway; we’ll tell you when we’ll be ready.

Subprocessors & data processing

Sylo relies on a small, vetted set of third-party processors to run the service: cloud infrastructure and database, telephony and messaging carriage, AI runtime and language models, payment processing, transactional email, and operational monitoring. Each is bound by a Data Processing Agreement, and international personal-data transfers are governed by Standard Contractual Clauses. We don’t publish an itemized vendor list; where a customer’s contract requires vendor disclosure, we provide it under NDA as part of that agreement. Tenants receive 30 days’ notice before any new category of subprocessor begins processing their data.

Data-processing terms are in our Data Processing Addendum; security questions to info@wayhow.ai.

Have a security question we didn’t answer?

Send it to info@wayhow.ai. We read everything and reply with what we know and what we don’t.