SOC 2 Type IPlanned · pre-launchOur full internal control set is implemented and monitored with automated evidence collection; an independent Type I audit is the next step.
SOC 2 Type IIPlanned · post-launchType II requires an observation period; it starts once a Type I report lands.
Penetration testPlanned · pre-launchWe intend to commission an independent third-party test of auth, payments, tenant isolation, and webhook security before general availability.
EncryptionIn transit and at rest.
Customer data is encrypted in transit (TLS 1.3) and at rest in our database. Voice recordings and transcripts inherit the same posture as the rest of your data.
- TLS 1.3 for all client + server traffic
- At-rest encryption on database, file storage, and backups
- Secrets in a dedicated store; no plaintext in source or logs
Tenant isolationYour data, your tenant. By design.
Every row of data carries a tenant identifier. Row-level security in the database enforces that boundary on every read and write, not optionally at the application layer.
- Row-level security policies on every public table
- A second tenant-scope check in the AI retrieval layer: your data is re-verified as yours before any model sees it
- No cross-tenant learning: your knowledge base never trains another tenant's AI
Identity & accessTwo-factor enforced for our staff. SSO for your enterprise.
Every Wayhow staff account must enroll two-factor authentication before our admin tools open at all, and each staff member sees only the sections their role grants. Your accounts can turn on multi-factor with recovery codes, and enterprise teams can sign in through their own identity provider with SAML single sign-on.
- Two-factor is REQUIRED for all Wayhow staff, and available (with recovery codes) on every customer account
- SAML single sign-on for enterprise teams, with domain-based auto-provisioning
- No “log in as you” impersonation: staff access to tenant data is credentialed, on request, and itself audited
- Least-privilege access to production systems
Observability without leakageLogs carry outcomes, not conversations. And they can't be rewritten.
Our monitoring captures errors, latencies, and call metadata, never the contents of customer conversations. Administrative actions land in an audit log the database itself refuses to edit or delete, and account owners have their own activity log showing which of their team members changed what.
- Conversation content lives in your dashboard, never in logs or error tracking
- A tamper-proof audit log: the database rejects edits and deletions, even by us
- Owners see their own team's activity: who changed settings, hours, or knowledge, and when
- A redaction filter drops known-sensitive fields before logs leave our systems
ResilienceBuilt to stay up, and to fail loudly, never silently.
The phone line is the product, so availability is engineered, not hoped for. Our voice stack detects a failing upstream provider, switches itself to a healthy one, and switches back automatically once the outage clears; a paging system wakes a human either way.
- Self-healing failover on the voice stack: outages are auto-detected, rerouted, and auto-reverted, proven in production
- A web application firewall with adaptive rate limiting shields every public surface
- Synthetic probe calls continuously verify the line actually answers, not just that servers are green
Recording consentCompliant with your state's rules.
Sylo detects the caller's state from area code and applies the right disclosure script (one-party or two-party consent) for that jurisdiction. Disclosures are logged per call.
- State-aware recording-consent script
- EU/GDPR consent script for international callers
- Audit log of every disclosure played
Your data is yoursExport it or delete it, any time.
From your dashboard you can export everything Sylo holds for your business as a single file, or permanently delete your account and all of its data, no support ticket required.
- One-click data export (right to access / portability)
- Self-serve account deletion (right to erasure) with full cascade
- 30-day data availability window after cancellation
What we haven’t earned yet, and won’t claim.
We don’t have a SOC 2 Type II report yet. We don’t have HIPAA certification; Healthcare is a separately gated tier we haven’t activated. We don’t claim ISO 27001 or HITRUST. Anyone in this category is either being honest about a pre-launch posture or stretching. We’d rather miss a quarter than ship a claim we can’t back.
If you need any of the above contractually today, we’re not the right fit yet, and we’ll say so on the discovery call. Talk to us anyway; we’ll tell you when we’ll be ready.
Subprocessors & data processing
Sylo relies on a small, vetted set of third-party processors to run the service: cloud infrastructure and database, telephony and messaging carriage, AI runtime and language models, payment processing, transactional email, and operational monitoring. Each is bound by a Data Processing Agreement, and international personal-data transfers are governed by Standard Contractual Clauses. We don’t publish an itemized vendor list; where a customer’s contract requires vendor disclosure, we provide it under NDA as part of that agreement. Tenants receive 30 days’ notice before any new category of subprocessor begins processing their data.
Data-processing terms are in our Data Processing Addendum; security questions to info@wayhow.ai.