Security & data protection
Real-time AI. Real privacy.
SonicR1 listens in real time — so privacy can't be an afterthought. Here's how your conversations are handled, in plain terms, backed by how the system actually works.
Last reviewed August 2026
- EU data residency
- Encrypted in transit & at rest
- Per-workspace isolation
- PII redacted before AI
- Keys in a separate vault
Full live coaching. No recording kept.
Run SonicR1's real-time sales coach on a live call without recording it. In Ephemeral mode no recording of the call is kept — no audio, transcript, notes or debrief are saved, and the coaching is gone the instant the call ends. Live speech is processed in the moment through our EU speech and AI processing to generate the coaching; the speech provider deletes audio and transcripts within one day, and SonicR1 stores no audio, transcript or notes from the call. Technical log and billing metadata may remain.
- No audio stored
- No transcript kept
- No notes persisted
- Gone when the call ends
SonicR1 stores no audio from your live calls. Ephemeral is the default; if you'd rather keep a record, switch to AI notes to save a transcript and summary (no recording) for follow-up — with consent, and you choose per call. A recording you upload yourself is a separate case: that file is stored so you can play it back, and deleting the call deletes it.
EU data residency by default
New workspaces default to EU-only, and EU is the fail-safe on any error. AI requests for EU-region workspaces are processed exclusively on EU endpoints (Frankfurt and Google's EU multi-region) with EU-only fallbacks — non-EU regions are dropped, never used as a silent fallback. App compute is pinned to Frankfurt (fra1).
Personal data redacted before AI sees it
Contact details are detected and swapped for tokens before the model call on the coaching paths — and an egress guard blocks any prompt that carries no redaction provenance.
One tenant can never read another
Per-workspace Row-Level Security, an authorization guard on every privileged route, and cross-tenant isolation tests in CI.
Encrypted, with keys kept apart
Encrypted in transit (TLS) and at rest. Detected PII is stored with AES-256-GCM, and those keys live in a separate vault.
Your data, your call
Consent-gated capture, no audio from your live calls stored, configurable retention, and hard deletion per call.
- Primary AI region
- EU · Frankfurt + Google EU multi-region
- AI fallbacks
- EU-only — non-EU dropped
- App compute region
- Frankfurt (fra1)
- Speech-to-text
- EU endpoints (default)
- Encryption in transit
- TLS (provider-terminated)
- PII value encryption
- AES-256-GCM, keys in a separate vault
Ephemeral (live-only)
Privacy-firstThe default. No recording of the call is kept — no audio, transcript, notes or debrief. Coaching happens live and is gone when the call ends. Live speech is processed through our EU speech processing, from which the provider deletes audio and transcripts within one day; technical log and billing metadata may remain.
AI notes
No audio from the live call is stored. With consent, a transcript and AI summary are saved for your follow-up — no recording.
Uploaded recording
A file you upload yourself is stored so you can replay it, and is deleted with the call.
AI transparency
How the AI handles your conversations
Enterprise endpoints, in the EU
Conversations are processed on enterprise AI endpoints in the EU — not consumer API keys.
Not used to train public models
Your calls aren't used to train publicly shared models. The contractual terms are in our DPA.
Redacted before the model
Contact and financial identifiers are tokenized before the model call on the coaching paths; personal names are additionally tokenized in post-call analysis.
You stay in control
The rep decides what to say — SonicR1 assists live, it never acts on its own.
Security questions? Reach our team at security@sonicr1.com.
Runs on eight named subprocessors, listed with legal entity, region and transfer mechanism in Annex 2 of our DPA. The customer records we host and all AI inference stay in the EU; limited further data — background-job step state, transactional e-mail and hosting logs — is held in the US.
Built on SOC 2 / ISO 27001-certified infrastructure provided by our hosting subprocessors.
Need the details for your security review?
We're happy to walk your team through the architecture. Our Data Processing Agreement (DPA), including subprocessors and technical measures, is published in full.