Security overview

SonicR1 — Security at a glance

A concise, shareable summary for your security review. The full DPA is published at sonicr1.com/dpa; the questionnaire (CAIQ / SIG Lite) is available on request.

Last updated August 2026

Hosting regionEU · Frankfurt
EncryptionTLS + AES-256-GCM
Tenant isolationRLS + CI tests
AI processingEU enterprise endpoints
Key storageSeparate vault
Security contactsecurity@sonicr1.com

Data protection

Where is customer data processed and stored?
Customer content — calls, transcripts, AI outputs and knowledge base — is stored in the EU, and AI requests are processed only on EU endpoints; non-EU is never used as a silent fallback. Limited further data — background-job step state, transactional e-mail and hosting logs — is held outside the EU and is listed in section 11.5 and Annex 2 of our DPA.
Is data encrypted in transit and at rest?
Yes — TLS in transit and at rest. Detected PII values are additionally stored with AES-256-GCM; keys are held in a separate vault from the app credentials.
Is personal data sent to AI providers?
Contact and financial identifiers are detected and replaced with tokens before the model call on the coaching paths; personal names are additionally tokenized in post-call analysis. A central egress guard blocks prompts that lack redaction provenance.
Are customer calls used to train AI models?
Conversations are processed on enterprise AI endpoints (not consumer API keys) and aren't used to train publicly shared models. Contractual terms are in the DPA.

Access & isolation

How is one tenant's data isolated from another's?
Row-Level Security is workspace-scoped across tenant tables, an authorization guard backstops privileged routes, and cross-tenant isolation tests run in CI.
How do users authenticate?
Supabase Auth — email and Google OAuth. SAML/OIDC single sign-on is not available yet; ask us if you need it.
Can customers delete their data?
Yes. Capture is consent-gated, audio storage is off by default, retention is configurable, and hard deletion is available per call — individually or in bulk. Deleting the account itself is self-service in Settings: the request is held for 24 hours and can be cancelled at any point in that window. There is no self-service control for deleting a workspace — a workspace is wound down as part of the account deletion of the person who owns it and is its only member, and then sits in a 30-day retrieval window before it is purged. Someone who owns a workspace that other members are still in is refused deletion until they hand that workspace to another member, or write to legal@sonicr1.com to arrange it manually.

Hosting & operations

Which infrastructure providers are used?
Eight subprocessors, listed in full with legal entity, region and transfer mechanism in Annex 2 of our DPA. The customer records we host and all AI inference stay in the EU (Frankfurt and Dublin); background-job step state, transactional e-mail and hosting logs are held in the US.
Are the data centers certified?
The underlying infrastructure is operated on SOC 2 / ISO 27001-certified data centers; those certifications are held by the providers, not by SonicR1.
What call-recording options exist?
Two modes, chosen per call. Ephemeral live-only: no call content is saved — no audio, transcript or notes; limited technical, billing and consent-attestation metadata may remain. AI notes: only a transcript and summary are saved, never the audio. In neither live mode is a customer call recorded. A recording you upload yourself is stored so you can replay it, and is deleted with the call.

Questions from your security team?

Reach us at security@sonicr1.com request full questionnaire & dpa.