Trust, Security & Compliance

People use Heardsafe to write down things they cannot safely say out loud. That sets the bar for how we handle their data. This page describes what we actually do today, what we do not yet do, and what we are building next.

1. Where your data goes

Heardsafe is not self-contained. Converting a conversation into a structured record requires sending its content to AI providers, and reaching you by phone or email requires telecoms and mail providers. These are our sub-processors and what each one receives.

Sub-processorReceivesPurpose
AnthropicConversation and incident contentAssistant responses, structured extraction
OpenAIConversation and incident contentFallback processing when the primary provider is unavailable
TwilioPhone number, call audio, SMS contentVoice line and text messaging
ElevenLabsCall audio and transcriptsConversational voice
SendGridEmail address, message contentTransactional email
Hosting providerAll stored data, at restApplication and database hosting

We do not sell personal information, and we do not disclose an individual's records to their employer. Full detail is in our Privacy Policy.

2. Security controls

ControlStatusDetail
Encryption in transitIn placeHTTPS enforced site-wide with HSTS; plain HTTP is redirected, not served.
Credential storageIn placePINs and admin passwords are stored as bcrypt hashes, never in plaintext or reversible form.
Session hardeningIn placeSession cookies are HttpOnly and SameSite=Lax, and Secure-only in production. Sessions expire on a configured timeout.
SQL injection defenceIn placeDatabase access goes through parameterised prepared statements.
CSRF protectionIn placeState-changing forms carry per-session CSRF tokens.
Rate limitingIn placeAuthentication endpoints are rate limited per IP and per account.
Audit loggingIn placeSignificant account and record actions are written to an audit log so access to sensitive records can be reviewed.
Browser hardening headersIn placeHSTS, X-Content-Type-Options, X-Frame-Options and Referrer-Policy are set at the edge.
Encryption at restIn placeIncident content and uploaded evidence are encrypted at rest, in addition to the storage-layer protection provided by our hosting provider.
Independent penetration testPlannedNot yet commissioned.
Single sign-on (SAML/SCIM)PlannedFor ClearView and BoardView enterprise deployments.

3. SOC 2

Heardsafe does not hold a SOC 2 report. Not certified We have not engaged an auditor and there is no observation window underway. We will not describe ourselves as SOC 2 compliant, aligned, or “audit-ready” until a report exists that we can send you.

Several of the controls in Section 2 map to the SOC 2 Security criteria, and the roadmap in Section 8 is ordered with an eventual Type II observation window in mind. If SOC 2 is a hard procurement gate for you, tell us — that information genuinely affects how we sequence the work.

4. UK and EU GDPR

Lawful basis

An individual using SafeVoice provides their information directly and consents to the processing described in our Privacy Policy. Where Heardsafe is deployed by an organization across its workforce, that organization is ordinarily the controller and Heardsafe the processor, governed by a Data Processing Agreement.

Data subject rights

Users may request access, correction, deletion, restriction, portability, and withdrawal of consent — including withdrawal from attorney referral. Requests go to help@heardsafe.com and we respond within the statutory period.

International transfers

Our sub-processors include US-based providers, so personal data may be transferred outside the UK and EEA.

DPIA — automated scoring

Heardsafe scores documented matters for legal merit, and that score influences whether a matter is offered to an attorney. This is automated processing of sensitive information about identifiable people, at scale, in a context where the individual is in a position of relative vulnerability. We treat it as high-risk processing for which a Data Protection Impact Assessment is required.

Scoring is not a legal assessment and predicts no outcome. Users may request human review of a score and may withdraw from referral entirely.

5. US privacy law

For California residents, we support the access, deletion, correction and opt-out rights provided by the CCPA as amended by the CPRA. We do not sell personal information as that term is defined, and we do not share it for cross-context behavioural advertising.

6. Data retention

We keep information only as long as there is a reason to. The schedule below is what we operate to. Two things shape it: records need to outlive the legal deadlines that apply to workplace claims, and nothing should sit on our systems once that purpose has passed.

WhatKept forMeasured from
Account and incident recordsLife of the account
Account deleted at your requestPurged within 30 daysDeletion request. The 30 days is a recovery window in case the request was a mistake.
Dormant accounts24 months, then 30 days’ notice before deletionLast sign-in
Uploaded evidenceWith its incident; purged 30 days after that incident is deletedIncident deletion
Call audio90 daysCall date. The transcript is kept with the incident; the recording itself is not.
Conversation messages and transcriptsWith their incident
Case scoresWith their incident
Matters referred to an attorney7 yearsReferral date. Retained to evidence what was shared, with whom, and on what basis.
Audit logs24 monthsEvent date
Email and SMS queue90 days after deliveryDelivery
Rate-limiting records30 daysEvent date
Generated exports and temporary files24 hoursGeneration
Backups35 days, rollingBackup date

The 24-month default is deliberate. Deadlines for workplace claims run from roughly 30 days for some safety complaints to about two years for wage and hour matters, so a record deleted at twelve months could disappear while a claim is still live.

You can delete an individual record or your whole account at any time without waiting for these periods. Deletion removes content from live systems immediately and from backups as those backups age out. Where we are legally required to keep something — or where a matter has already been referred to an attorney at your direction — we retain only what that obligation requires and nothing further.

7. Reporting a vulnerability

If you believe you have found a security issue, email help@heardsafe.com with enough detail to reproduce it. We will acknowledge receipt, keep you updated, and will not pursue legal action against researchers who investigate in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before disclosing it.

8. Ask us anything

Security questionnaires, DPA requests and architecture questions go to help@heardsafe.com. If the honest answer to a question is “not yet”, that is the answer you will get.

Related: Privacy Policy · Terms of Service · UK Corporate Governance Code, Provision 29