Skip to content

Legal

Security

Conversations are among the most sensitive data an organisation handles. This is how we treat them, and how to tell us when we have got something wrong.

Last updated July 1, 2026

Encryption

All traffic is encrypted in transit with TLS 1.3. Audio streams use DTLS over WebRTC where the client supports it. Any data written to durable storage — which happens only when a workspace opts in to retention — is encrypted at rest with AES-256.

Data minimisation

The most reliable way to protect conversation data is not to keep it. Zero-retention mode is the default, and it means audio buffers live in memory only as long as the packet being processed. Nothing is written to disk, and nothing survives the session.

Access control

Production access requires hardware-backed multi-factor authentication and is granted per-role, not per-person-forever. Access to any system that can touch customer conversation data is logged, reviewed quarterly, and revoked automatically when a role changes.

Infrastructure

Workloads run in isolated environments per region. EU and US processing planes share no compute or storage. Deployments are immutable and rolled forward; there is no interactive shell on production inference nodes.

Compliance

SOC 2 Type II is in progress and targeted for completion alongside general availability. GDPR data processing agreements are available today. HIPAA-eligible configurations are on the roadmap for healthcare deployments and are not yet available.

Reporting a vulnerability

Write to security@babelgo.ai. We acknowledge reports within one business day and aim to remediate critical issues within seven days. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and give us reasonable time to fix an issue before disclosure.