Skip to content

The boring, essential part

Built for the questions procurement asks.

Single tenant by construction, with the controls a regulated buyer expects already present rather than on a roadmap.

How it works

What the capability actually does.

Single tenant, by construction

Each deployment is one business with its own database and credentials. There is no shared runtime, so a customer conversation cannot reach another customer even in principle.

An audit log that answers why

Every meaningful admin action is recorded with who did it and when, including every call an outside MCP client makes. Combined with the event log and per-turn transcripts, you can trace why the system called a particular person.

Retention and erasure

Set how long transcripts, events, and messages are kept, and change it without a restart. A single request erases everything tied to a phone number or email address. Both ship in every plan including the free one.

Least privilege for machines too

An API key carries one scope per capability rather than a single all-or-nothing grant, and there is deliberately no wildcard. A key that only needs to read transcripts cannot place a call.

Hardened against its own configuration

Every admin-supplied URL is checked before it is called, with the resolved address pinned to defeat DNS rebinding. Credentials are encrypted at rest. Webhook deliveries are signed.

In the product

The screens this happens on.

The audit log listing admin actions with actor, resource, and timestamp

Who changed what, and when

Every meaningful administrative action, with who did it and when, including every call an outside MCP client makes. Read alongside the event log and the per-turn transcripts, it answers the question a regulated buyer actually asks, which is not what the system did but why it did it to that particular person.

  • Never purged, unlike transcripts and events
  • Readable by owners and admins only
Boundaries

What it deliberately does not do.

Stated here rather than discovered in production. Every one of these is a real constraint, and knowing them before you buy is worth more than a longer feature list.
  • Roles are deployment-wide. There is no organisation or workspace separation inside one deployment, because a deployment is one business.
  • Rate limiting is per process, which is a consequence of running as a single instance.
  • We hold no certification on your behalf. Self-hosting means the compliance posture is yours, which is the point for most buyers who ask.