Trust Centre
Security, privacy and responsible voice AI.
Deploy in-region or on-premise. Your audio doesn't have to leave the country to become text.
Security
How we protect the platform.
Encryption in transit & at rest
All data is encrypted in transit (TLS) and at rest.
API-key security
Keys are hashed at rest and scoped per project.
Infrastructure isolation
CallRolin runs on cloud infrastructure hosted with Google Cloud, with network separation between customer workloads and internal systems. Access to production systems is restricted to authorized personnel only. Enterprise customers can opt for on-premise deployment for in-country or in-environment data residency. [[ confirm any specifics you want to state publicly ]]
Access control
Role-based access control across the platform.
Vulnerability management
We monitor our systems and dependencies for known vulnerabilities and apply security patches on a regular basis. Critical issues are prioritized for prompt remediation. [[ confirm patch cadence if you want to commit to one publicly ]]
Backups
Account and configuration data are backed up regularly to protect against data loss. [[ confirm backup frequency and retention period ]]
Incident response
In the event of a security incident, we investigate promptly, take steps to contain and remediate, and notify affected customers where appropriate. [[ confirm your notification commitment / timeframe ]]
Responsible disclosure
Email hello@callrolin.com with the subject line "Security Disclosure." We support responsible disclosure and will work with you to resolve verified issues.
Privacy
What happens to your data.
What's collected
Account and contact details, the text and audio you send to the API, usage and request logs, and billing data (handled by Paddle). See our Privacy Policy for full detail.
Is text/audio stored
Yes. The text and audio you submit, along with the output generated from them, are processed on CallRolin's cloud infrastructure (Google Cloud) in order to deliver the Service. Enterprise customers can use on-premise deployment so that data stays within their own environment.
Retention options
Request logs are retained for 30 days and then deleted. Billing records may be retained longer where required by law. You can request deletion of your data at any time.
Does customer data train models
Yes. CallRolin may use customer audio and text to improve and train its voice models. Standard processing takes place on CallRolin's cloud infrastructure (Google Cloud); Enterprise on-premise deployment keeps data within your own environment.
Deletion
Email hello@callrolin.com with the subject line "Data Request" to request deletion of your data. We aim to respond within 30 days.
Regional hosting
Standard plans (Starter/Business): data is processed on CallRolin's cloud infrastructure, hosted with Google Cloud. Enterprise: on-premise deployment so that audio and data never leave your own environment — supporting SBP and PTA compliance requirements. Data is not transferred outside Pakistan except under custom arrangements agreed in writing with the customer.
Compliance
Where we stand today.
Current status
Planned — no certifications completed yet.
Planned certifications
[[ list only the certifications you are genuinely pursuing, e.g. ISO 27001 / SOC 2 — leave empty if none yet ]]
Security docs
Available to Enterprise customers on request. [[ confirm ]]
Responsible Voice AI
Voices belong to the people who made them.
Owner consent
Custom voices require the voice owner's explicit consent before training.
Custom-voice approval
Every custom voice request goes through a manual approval process.
Impersonation limits
CallRolin prohibits using synthetic voices to impersonate real people without explicit, verifiable consent. Use for fraud, defamation, disinformation, or harassment is strictly prohibited. See our Acceptable Use Policy and Voice AI Policy for full terms.
Voice deletion
You may request deletion of a custom voice and its underlying training data at any time by emailing hello@callrolin.com. Approved deletions are completed within 30 days.
System Status
Illustrative status — not a live feed yet.