← Callora home
Trust

Boring is the point.

Voice agents talk to your customers. That means we take security seriously. Here’s exactly what we do, in plain English.

TCPA compliant

All outbound campaigns include explicit consent tracking, DNC scrubbing, and calling-window enforcement per FCC 47 CFR § 64.1200.

GDPR ready

EU customers get standard DPA. Data subject requests (Art. 15/17) are self-serve via Dashboard → Settings → Privacy.

HIPAA architecture

Encryption at rest (AES-256-GCM per field), encryption in transit (TLS 1.3), tenant isolation, immutable audit log. BAA available on Business tier.

SOC 2 Type I — in progress

Type I readiness assessment underway. Expected: Q3 2026. Type II attestation to follow after 6 months of evidence collection.

Uptime

99.9% SLA on Business tier (Callora) and Locum Pro / Agency (Medora). Live status page rolling out — subscribe at security@call.metis.gold for status alerts in the meantime.

Responsible disclosure

Report vulnerabilities to security@call.metis.gold. Coordinated disclosure preferred; hall of fame + swag for verified reports.

Last updated: August 25, 2026.
Subprocessors: OpenAI (voice + LLM), Twilio (telephony), Stripe (billing), Google (Workspace integrations), Cloudflare (WAF/CDN), MongoDB Atlas (data), Emergent (hosting), Resend (transactional email), Sentry (error tracing, PHI-scrubbed).
Data residency: US-East by default. EU-region option on Business tier.
Contact: security@call.metis.gold · privacy@call.metis.gold