Security
We take security seriously. Here's what that means.
Shilo records and analyzes your team's sales conversations, which means we hold some of the most sensitive records your business produces. This page explains how we protect them, in plain English. If your security team wants the deeper technical version, reach out and we'll walk them through it.
Security at a glance
AES-256
Encryption for all customer data at rest
TLS 1.2+
Encryption for everything in transit
US-only
Data residency, with no offshore processing
MFA
Required on every internal system
The practices
How we protect your data
Encrypted everywhere
Every conversation, transcript, and record is encrypted with AES-256 at rest and TLS 1.2 or higher in transit. Nothing moves over plain HTTP, inside our systems or out.
Hosted in the US, and only the US
All production systems and customer data live on cloud infrastructure physically located in the United States. No offshore data centers, no international backups. Data is replicated across multiple US availability zones so an outage in one doesn't take you down.
Access on a need-to-have basis
Role-based access control applies the least-privilege principle to every employee: access is reviewed periodically, stale permissions are revoked, and every access event is logged. Internal systems require multi-factor authentication, with hardware security keys (WebAuthn/FIDO2) for phishing-resistant sign-in.
Watched around the clock
Critical systems are monitored 24/7 with automated alerts for anomalous behavior or unauthorized access attempts. A documented incident response plan defines roles and escalation paths, and every incident ends with a post-incident review.
Built securely from the first commit
Code reaches production only after mandatory peer review. Automated static analysis and dependency scanning run continuously, secrets live in secure vaults, and independent third parties run periodic penetration tests against our systems.
Vendors held to the same bar
Every third-party vendor is assessed for security and compliance risk before onboarding. We sign Data Processing Agreements where applicable and re-review high-risk vendors annually.
Data lifecycle
Your data, on your terms
We keep data only as long as it's useful to you or required of us. Our privacy policy spells out what we collect, the legal bases for processing it, and your rights under regulations like the CCPA. We review it annually.
- While you're a customer
- Call audio and transcripts stay available in your workspace for as long as you need them.
- Inactive recordings
- Purged 30 days after deactivation.
- Application logs
- Kept 90 days in active systems, then archived for 12 months.
- Backups
- Daily encrypted snapshots, retained for 60 days.
- If you leave
- All customer data is securely deleted within 30 days of your request or contract end. We use cryptographic erasure, so it's unrecoverable from backups and replicas too.
Common questions
Answers your team will ask for
Is my call data encrypted?
Yes. All customer data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit.
Where is my data stored?
On cloud infrastructure physically located in the United States, replicated across multiple US availability zones. Shilo uses no offshore data centers, managed services, or international backups.
What happens to my data if I cancel?
All of your data is securely deleted within 30 days of your request or contract end, using cryptographic erasure so it can't be recovered from backups.
How do I report a security vulnerability?
Email [email protected] with steps to reproduce. We read every report, and we ask for reasonable time to fix an issue before any public disclosure.
Evaluating Shilo?
We'll complete your security questionnaire, review architecture with your team, and sign Data Processing Agreements where applicable. Contact us and we'll set it up.
Found a vulnerability?
Email [email protected] with steps to reproduce. We read every report. Please avoid accessing customer data in your research and give us reasonable time to remediate before disclosing publicly.
Take Your Team to
the Next Level