TRUST & SECURITY
Your Data. Your Keys.
Our Responsibility.
SoloMatic is built on a simple principle: you should never have to trade control for convenience. Every integration, every agent, every workflow — you own the infrastructure, we manage the intelligence.
Data Ownership
✓You own every account. SoloMatic never takes ownership of your CRM, phone numbers, API keys, or customer data.
✓Every API key, every CRM contact, every third-party account is yours. If you ever leave, your data and accounts stay with you.
✓SoloMatic manages the intelligence layer — agent configuration, workflows, and optimization. We do not claim ownership of your infrastructure.
Encryption & Data Protection
✓All data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256.
✓API keys are stored with additional encryption layers, never logged in plaintext, and never exposed in prompts or outputs.
✓Each client's data is isolated with row-level security in our database. No cross-tenant data leakage.
API Key & Credential Handling
✓You connect your own API keys (OpenAI, Twilio, Vapi, n8n, CRM, etc.) through your secure portal. SoloMatic never requests your master credentials.
✓Keys are stored encrypted and only used for the specific workflows you authorize during onboarding.
✓You can revoke or rotate any key at any time through your provider's dashboard. SoloMatic has no independent access.
Infrastructure & Hosting
✓SoloMatic applications are hosted on Netlify (static frontend) and Supabase (database + serverless functions), both SOC 2 compliant platforms.
✓Voice and telephony infrastructure runs on Twilio and Vapi, both SOC 2 and HIPAA-compliant where configured.
✓AI model inference runs through OpenRouter, Anthropic, OpenAI, and other providers — routed through your own API keys.
Data Retention & Deletion
✓You retain full control over your data retention policies through your portal settings.
✓Upon cancellation, your data remains accessible for 30 days for export. After 30 days, it is permanently deleted.
✓Raw data, CRM contacts, and third-party accounts remain yours after cancellation. You lose access to SoloMatic's managed intelligence layer.
Compliance & Certifications
✓SoloMatic infrastructure partners (Netlify, Supabase, Twilio, Vapi) maintain SOC 2 compliance.
✓HIPAA-compliant configurations are available for healthcare and dental clients. Contact us to confirm scope during onboarding.
✓We do not claim certifications we have not earned. Compliance status is verified on a per-client basis during onboarding.
Permissions & Approval Controls
✓Every SoloMatic agent operates under least-privilege permissions. Agents can only access the tools and data explicitly authorized.
✓High-risk actions (payments, refunds, customer data deletion, large outbound campaigns, production infrastructure changes) require explicit human approval.
✓All agent actions are logged for audit. You can review your agent's activity history in your portal.
Subprocessors & Third-Party Access
✓SoloMatic does not sell your data. Period.
✓Third-party model providers (OpenAI, Anthropic, Google, etc.) process data only as needed for inference and only through your own API keys.
✓A full list of subprocessors is available upon request during onboarding.
Have specific security questions?
Contact Our Team →