§01 · Security

Designed for controlled rollout and procurement review.

TalkSonar supports sales-led implementation, provider-aware setup, access boundaries, and reviewable data-handling discussions for teams evaluating speech analytics.

Editor's note

This page is maintained by TalkSonar to answer common security and privacy questions about the platform. It is app-owner content, not an independent certification or verification.

§02What TalkSonar processes
  • Call audio and transcripts
  • CRM context
  • Extracted analysis outputs
  • CRM notes and summaries
  • Dashboard metrics
§03Controlled implementation
  • Sales-led onboarding
  • First project scoping
  • Provider configuration
  • Validation before expansion
  • Security and procurement review during rollout
§04Implemented application controls

Explicit boundaries in
requests and background work.

These controls are present in the application code. Infrastructure topology, identity provider, storage settings, retention, and contractual requirements remain specific to each deployment and must be confirmed during implementation.

  • Authenticated and role-restricted access

    Protected application routes require an authenticated principal; administrative routes apply explicit role checks.

  • Organization-scoped data access

    Customer-data routes carry organization context and use organization-scoped database sessions with row-level policies.

  • Organization context in background work

    Customer task messages, provider limits, caches, and processing artifacts carry organization scope instead of relying on a global default.

  • Privileged-action audit events

    Cross-organization administrative actions are recorded with the acting principal, target organization, action, and correlation context.

§05Access and data boundaries

Organization-aware access.
Provider-aware configuration.

TalkSonar is designed around organization-aware access and implementation-specific provider configuration. Exact deployment and data-handling details are reviewed during rollout planning.

§06AI data use

Reviewed in the
implementation process.

Customer data-use terms, AI provider settings, retention, deletion, and training-related language must be reviewed in the implementation and legal process.

§07Subprocessors and providers

Provider categories
TalkSonar can route through.

Actual subprocessor selection per customer is configured during implementation and recorded in the procurement materials. The list below is the catalog of categories and provider options, not a per-deployment confirmation.

  • Speech-to-text

    Transcribe call audio for analysis.

    • Soniox
    • Deepgram (roadmap)
    • Whisper (roadmap)
    • Yandex SpeechKit (roadmap)
  • LLM routing

    Run analysis prompts against configured language models.

    • OpenRouter
    • OpenAI (roadmap)
    • Anthropic (roadmap)
    • Local gateway (roadmap)
  • CRM

    Read CRM context and publish notes/summaries back.

    • AmoCRM
    • Bitrix24 (roadmap)
    • HubSpot (roadmap)
    • Salesforce (roadmap)
  • Telephony

    Source call recordings and metadata.

    • Sipuni
    • Twilio (roadmap)
  • Storage

    Hold call audio and derived artifacts during processing.

    • S3 / MinIO

Roadmap providers are not yet generally available. Region-, residency-, and DPA-specific constraints are reviewed during rollout planning.

§08Procurement FAQ

Questions we hear.

What data does TalkSonar process?
Call audio and transcripts, CRM context, extracted analysis outputs, and the CRM notes and summaries TalkSonar publishes back.
Can we review providers and subprocessors?
Yes. Subprocessors and providers can be reviewed as part of the implementation process.
Does TalkSonar sign a DPA?
DPA terms are reviewed during the implementation and legal process.
What retention options exist?
Retention configuration is reviewed during rollout planning based on your data-handling requirements.
Is TalkSonar SOC 2 or ISO 27001 certified?
TalkSonar does not publish certifications it has not completed. Certification status and roadmap can be reviewed during procurement.
Can TalkSonar support region-specific constraints?
Provider and storage choices are evaluated during the implementation conversation.

Talk to us about your security review.

We will share what we can up front and route procurement-specific questions to the right path.