Security overview
SonicR1 — Security at a glance
A concise, shareable summary for your security review. The full DPA is published at sonicr1.com/dpa; the questionnaire (CAIQ / SIG Lite) is available on request.
Last updated August 2026
Hosting regionEU · Frankfurt
EncryptionTLS + AES-256-GCM
Tenant isolationRLS + CI tests
AI processingEU enterprise endpoints
Key storageSeparate vault
Security contactsecurity@sonicr1.com
Data protection
- Where is customer data processed and stored?
- Customer content — calls, transcripts, AI outputs and knowledge base — is stored in the EU, and AI requests are processed only on EU endpoints; non-EU is never used as a silent fallback. Limited further data — background-job step state, transactional e-mail and hosting logs — is held outside the EU and is listed in section 11.5 and Annex 2 of our DPA.
- Is data encrypted in transit and at rest?
- Yes — TLS in transit and at rest. Detected PII values are additionally stored with AES-256-GCM; keys are held in a separate vault from the app credentials.
- Is personal data sent to AI providers?
- Contact and financial identifiers are detected and replaced with tokens before the model call on the coaching paths; personal names are additionally tokenized in post-call analysis. A central egress guard blocks prompts that lack redaction provenance.
- Are customer calls used to train AI models?
- Conversations are processed on enterprise AI endpoints (not consumer API keys) and aren't used to train publicly shared models. Contractual terms are in the DPA.
Access & isolation
- How is one tenant's data isolated from another's?
- Row-Level Security is workspace-scoped across tenant tables, an authorization guard backstops privileged routes, and cross-tenant isolation tests run in CI.
- How do users authenticate?
- Supabase Auth — email and Google OAuth. SAML/OIDC single sign-on is not available yet; ask us if you need it.
- Can customers delete their data?
- Yes. Capture is consent-gated, audio storage is off by default, retention is configurable, and hard deletion is available per call — individually or in bulk. Deleting the account itself is self-service in Settings: the request is held for 24 hours and can be cancelled at any point in that window. There is no self-service control for deleting a workspace — a workspace is wound down as part of the account deletion of the person who owns it and is its only member, and then sits in a 30-day retrieval window before it is purged. Someone who owns a workspace that other members are still in is refused deletion until they hand that workspace to another member, or write to legal@sonicr1.com to arrange it manually.
Hosting & operations
- Which infrastructure providers are used?
- Eight subprocessors, listed in full with legal entity, region and transfer mechanism in Annex 2 of our DPA. The customer records we host and all AI inference stay in the EU (Frankfurt and Dublin); background-job step state, transactional e-mail and hosting logs are held in the US.
- Are the data centers certified?
- The underlying infrastructure is operated on SOC 2 / ISO 27001-certified data centers; those certifications are held by the providers, not by SonicR1.
- What call-recording options exist?
- Two modes, chosen per call. Ephemeral live-only: no call content is saved — no audio, transcript or notes; limited technical, billing and consent-attestation metadata may remain. AI notes: only a transcript and summary are saved, never the audio. In neither live mode is a customer call recorded. A recording you upload yourself is stored so you can replay it, and is deleted with the call.
Questions from your security team?
Reach us at security@sonicr1.com — request full questionnaire & dpa.