SOLOMATIC
Deploying your AI workforce0%

PricingContactSign InRun Revenue Leak Audit
TRUST & SECURITY

Your Data. Your Keys.
Our Responsibility.

SoloMatic is built on a simple principle: you should never have to trade control for convenience. Every integration, every agent, every workflow — you own the infrastructure, we manage the intelligence.

Data Ownership

You own every account. SoloMatic never takes ownership of your CRM, phone numbers, API keys, or customer data.
Every API key, every CRM contact, every third-party account is yours. If you ever leave, your data and accounts stay with you.
SoloMatic manages the intelligence layer — agent configuration, workflows, and optimization. We do not claim ownership of your infrastructure.

Encryption & Data Protection

All data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256.
API keys are stored with additional encryption layers, never logged in plaintext, and never exposed in prompts or outputs.
Each client's data is isolated with row-level security in our database. No cross-tenant data leakage.

API Key & Credential Handling

You connect your own API keys (OpenAI, Twilio, Vapi, n8n, CRM, etc.) through your secure portal. SoloMatic never requests your master credentials.
Keys are stored encrypted and only used for the specific workflows you authorize during onboarding.
You can revoke or rotate any key at any time through your provider's dashboard. SoloMatic has no independent access.

Infrastructure & Hosting

SoloMatic applications are hosted on Netlify (static frontend) and Supabase (database + serverless functions), both SOC 2 compliant platforms.
Voice and telephony infrastructure runs on Twilio and Vapi, both SOC 2 and HIPAA-compliant where configured.
AI model inference runs through OpenRouter, Anthropic, OpenAI, and other providers — routed through your own API keys.

Data Retention & Deletion

You retain full control over your data retention policies through your portal settings.
Upon cancellation, your data remains accessible for 30 days for export. After 30 days, it is permanently deleted.
Raw data, CRM contacts, and third-party accounts remain yours after cancellation. You lose access to SoloMatic's managed intelligence layer.

Compliance & Certifications

SoloMatic infrastructure partners (Netlify, Supabase, Twilio, Vapi) maintain SOC 2 compliance.
HIPAA-compliant configurations are available for healthcare and dental clients. Contact us to confirm scope during onboarding.
We do not claim certifications we have not earned. Compliance status is verified on a per-client basis during onboarding.

Permissions & Approval Controls

Every SoloMatic agent operates under least-privilege permissions. Agents can only access the tools and data explicitly authorized.
High-risk actions (payments, refunds, customer data deletion, large outbound campaigns, production infrastructure changes) require explicit human approval.
All agent actions are logged for audit. You can review your agent's activity history in your portal.

Subprocessors & Third-Party Access

SoloMatic does not sell your data. Period.
Third-party model providers (OpenAI, Anthropic, Google, etc.) process data only as needed for inference and only through your own API keys.
A full list of subprocessors is available upon request during onboarding.

Have specific security questions?

Contact Our Team →