Security

We take security seriously. Here's what that means.

Shilo records and analyzes your team's sales conversations, which means we hold some of the most sensitive records your business produces. This page explains how we protect them, in plain English. If your security team wants the deeper technical version, reach out and we'll walk them through it.

Security at a glance

AES-256

Encryption for all customer data at rest

TLS 1.2+

Encryption for everything in transit

US-only

Data residency, with no offshore processing

MFA

Required on every internal system

The practices

How we protect your data

Encrypted everywhere

Every conversation, transcript, and record is encrypted with AES-256 at rest and TLS 1.2 or higher in transit. Nothing moves over plain HTTP, inside our systems or out.

Hosted in the US, and only the US

All production systems and customer data live on cloud infrastructure physically located in the United States. No offshore data centers, no international backups. Data is replicated across multiple US availability zones so an outage in one doesn't take you down.

Access on a need-to-have basis

Role-based access control applies the least-privilege principle to every employee: access is reviewed periodically, stale permissions are revoked, and every access event is logged. Internal systems require multi-factor authentication, with hardware security keys (WebAuthn/FIDO2) for phishing-resistant sign-in.

Watched around the clock

Critical systems are monitored 24/7 with automated alerts for anomalous behavior or unauthorized access attempts. A documented incident response plan defines roles and escalation paths, and every incident ends with a post-incident review.

Built securely from the first commit

Code reaches production only after mandatory peer review. Automated static analysis and dependency scanning run continuously, secrets live in secure vaults, and independent third parties run periodic penetration tests against our systems.

Vendors held to the same bar

Every third-party vendor is assessed for security and compliance risk before onboarding. We sign Data Processing Agreements where applicable and re-review high-risk vendors annually.

Data lifecycle

Your data, on your terms

We keep data only as long as it's useful to you or required of us. Our privacy policy spells out what we collect, the legal bases for processing it, and your rights under regulations like the CCPA. We review it annually.

While you're a customer
Call audio and transcripts stay available in your workspace for as long as you need them.
Inactive recordings
Purged 30 days after deactivation.
Application logs
Kept 90 days in active systems, then archived for 12 months.
Backups
Daily encrypted snapshots, retained for 60 days.
If you leave
All customer data is securely deleted within 30 days of your request or contract end. We use cryptographic erasure, so it's unrecoverable from backups and replicas too.

Common questions

Answers your team will ask for

Is my call data encrypted?

Yes. All customer data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit.

Where is my data stored?

On cloud infrastructure physically located in the United States, replicated across multiple US availability zones. Shilo uses no offshore data centers, managed services, or international backups.

What happens to my data if I cancel?

All of your data is securely deleted within 30 days of your request or contract end, using cryptographic erasure so it can't be recovered from backups.

How do I report a security vulnerability?

Email [email protected] with steps to reproduce. We read every report, and we ask for reasonable time to fix an issue before any public disclosure.

Evaluating Shilo?

We'll complete your security questionnaire, review architecture with your team, and sign Data Processing Agreements where applicable. Contact us and we'll set it up.

Found a vulnerability?

Email [email protected] with steps to reproduce. We read every report. Please avoid accessing customer data in your research and give us reasonable time to remediate before disclosing publicly.

Take Your Team to
the Next Level

Agent Coaching
Call Summary
Call Scoring
Transcripts & Sentiment
Book a Demo Bubble Animation