Security & Compliance
Truffl is not a telecom operator. We work with licensed telephony and communication providers to support customer communication workflows.
Encryption at rest and in transit for all customer data
Role-based access controls with least-privilege principles
Secure API key management and rotation policies
Audit logging for all administrative and configuration actions
Separation of customer data across platform tenants
Regular internal security reviews and dependency audits
Monitoring and alerting for unusual activity patterns
Secure credential handling and secrets management
Incident response process with defined escalation paths
Truffl is not a licensed telecom operator. We work with licensed telephony and communication providers to support customer communication workflows.
We operate within the framework of India's Digital Personal Data Protection Act (DPDPA) and advise customers on their obligations as data fiduciaries.
We provide tools to help configure call recording consent prompts. The obligation to obtain customer consent rests with the business deploying the workflow.
Our platform supports configuration of data retention periods so businesses can align with their own retention policies.
We can support customers requiring Data Processing Agreements (DPAs), Master Service Agreements (MSAs), or Statement of Work (SOW) documentation.
For regulated sectors (BFSI, healthcare, insurance), we work with customers to understand sector-specific compliance requirements and configure workflows accordingly.
We maintain audit logs that can be made available to customers for compliance and review purposes.
Truffl supports role-based access controls to help businesses limit access to sensitive call data.
We do not make representations about specific certifications (SOC 2, ISO 27001) without written confirmation. Contact compliance@trufflinnovations.in for current status.
Security review support is available for Enterprise customers as part of vendor onboarding processes.
Customer data processed through the Truffl platform is logically separated between tenants. We do not commingle customer call data, prompt configurations, or workflow analytics across accounts. Access controls are enforced at the API and storage layer.
We work with cloud infrastructure providers and telephony partners who maintain their own security certifications. The choice of AI model provider (used for voice processing and transcription) depends on your workflow configuration. Where customers have specific data residency requirements, we work with them to configure appropriate provider routing.
By default, Truffl does not use customer call recordings, transcripts, or business data to train third-party models unless explicitly agreed in writing.
Truffl is designed to deploy AI voice agents for legitimate business communication workflows. Our platform includes tools for configuring disclosure, consent, and escalation to ensure AI-assisted calls are handled responsibly. Customers are expected to deploy Truffl in compliance with applicable law and our Acceptable Use Policy. Workflows that facilitate deceptive, harassing, or unlawful communication are not permitted on the platform.
If you discover a security vulnerability or have a concern related to Truffl's systems or data handling, please contact our security team directly.
security@trufflinnovations.in