Security & Compliance
How we protect your data — and the agreements we sign.
SIPmind handles your customers' calls, messages, and records. We treat that data as yours, not ours. This page describes how it is protected, where it can live, and the contracts that put it in writing. Where a capability is provisioned per engagement rather than enabled by default, we say so.
SIPmind is built and operated by Techdab LLC, a United States company. It is available directly, or through certified local partners and integrators who can handle billing, deployment, and specific compliance requirements in your region.
Your data is yours — we are your processor
You remain the owner and controller of your data. SIPmind processes it only on your instruction, for the purpose of running your service — never for our own purposes, and never to train models for anyone else. We sign a Data Processing Agreement (DPA) with every customer that puts this in writing, including the list of subprocessors, security obligations, and data-deletion terms. We do not sell your data.
Encryption
All data is encrypted in transit (TLS 1.2+) and at rest. API keys and credentials are stored server-side only, never exposed to the browser or returned by our APIs, and shown masked in the interface.
Strict tenant isolation
Every account's data is scoped to its tenant in application code on every request — one customer's account cannot read, write, or even see another's. Row-level security is enabled at the database layer as an additional backstop.
Access control & auditability
Role-based access (administrator vs. operator) with least-privilege defaults: operators see conversations and leads, not settings, keys, or billing. Sensitive actions are logged, and device access (mobile / softphone) can be revoked instantly.
You choose where your data lives
This is where SIPmind goes further than a typical cloud product. You can:
- Regional data residency — our platform database is in the EU by default; where your jurisdiction requires the primary database to be in-country, we provision a dedicated in-region database and storage as part of the engagement.
- Run on your own telephony — connect your own PBX/SIP so live call audio is handled on your own infrastructure, a configuration proven in production. Live call audio is processed in real time by the AI model (OpenAI); under a BAA on eligible endpoints it is not retained. Records and recordings are stored in our database — EU by default, or in-region per the option above.
We adapt to your local data-protection requirements, localize storage where your jurisdiction mandates it, and sign the agreements your regulator expects. For data that does cross a border (for example, to an AI processor), we do so only on a lawful basis you control, and we name every recipient in your DPA.
Healthcare: HIPAA-ready
For healthcare customers, "HIPAA-ready" means a specific, provisioned setup. When you onboard, we provision your environment to meet the administrative, physical, and technical safeguards that HIPAA requires, sign a Business Associate Agreement (BAA), and put that protected setup in place before any protected health information is processed. It is built on HIPAA-eligible infrastructure.
There is no HIPAA "certification" to hold, so we claim none. What we provide is configured per practice — a signed BAA, an environment set to the required safeguards, and a clear division of responsibilities — put in place as soon as a healthcare customer comes on board.
Subprocessors, transparently
We rely on a small, vetted set of subprocessors for AI processing, database, and hosting. The current list — and the safeguards each one provides — is named in your DPA and available on request. We notify you before adding a new subprocessor that handles your data.
Retention & deletion you control
You decide how long data is kept. Call recordings, message attachments, and records have configurable retention with automatic deletion, and you can disable storage of sensitive attachments entirely. Deletion and export on request are part of our standard terms.
Incident response
We operate a documented detection and incident-response process and continuously monitor our systems. If an incident affects your data, we notify you promptly with the facts you need to meet your own obligations to your customers and your regulator.
Aligned with leading frameworks
Our security controls are designed around the objectives of SOC 2 and ISO 27001, and — for healthcare — HIPAA. We pursue formal, independent attestation in step with enterprise customer requirements. If you have a security questionnaire or need a specific control mapping, send it over — we answer them directly.
The agreements we sign
Trust should be in writing, not just on a page. With each customer we put in place:
- Data Processing Agreement (DPA) — roles, purposes, security obligations, subprocessors, deletion.
- Business Associate Agreement (BAA) — for healthcare customers handling protected health information.
- Confidentiality and a clear allocation of responsibilities between you (the data controller) and SIPmind (your processor).
Security questionnaire
The questions a security or procurement team usually asks — answered directly, including where a control is on our roadmap rather than in place today. Need a formal CAIQ / SIG or your own questionnaire completed? Send it to hello@sipmind.net and we'll return it directly.
Data & encryption
Is data encrypted?
Yes — in transit (TLS 1.2+) and at rest. API keys and credentials are stored server-side only, never returned by our APIs or exposed to the browser, and shown masked in the interface.
Where does our data live?
By default our platform database is in the EU. Where your jurisdiction requires the primary database to be in-country, we provision a dedicated in-region database as part of the engagement, and your telephony can run on your own infrastructure. The AI processor (OpenAI) is in the US — that step always crosses a border, on a lawful basis you control and named in your DPA.
Do you use our data to train AI?
No. We process your data only to run your service — never to train models for anyone else — and we never sell it. On our AI provider's API, customer data is not used to train their models, and we pursue Zero Data Retention on eligible endpoints for regulated workloads.
What is sent to the AI processor in another country?
Only the conversation text needed to answer, on a lawful basis you control (your customers' consent — we give you the wording). Sensitive records — for example medical results — stay in your own system; we don't process them. Every recipient is named in your DPA.
Access, authentication & isolation
How is one customer's data kept separate from another's?
Every account's data is scoped to its tenant in application code on every request — one customer cannot read, write, or even see another's. Row-level security is enabled at the database layer as an additional backstop.
How do users authenticate? Do you support MFA / SSO?
Dashboard and mobile logins use passwords that are stored hashed (never in plaintext); sessions are signed, expiring tokens; per-tenant API keys are stored as SHA-256 hashes. Access is role-based (administrator vs. operator, least-privilege), and device access can be revoked instantly. Multi-factor authentication and SSO/SAML are on our roadmap and are not enabled today.
Are administrator and sensitive actions logged?
Sensitive actions are logged, and we continuously monitor our systems with error tracking that is configured to exclude PII and secrets (frame locals and personal data are not sent to our monitoring provider).
Messaging channels & account safety
Can connecting SIPmind get our WhatsApp number or Instagram account banned?
No. We connect only through Meta's official interfaces — the WhatsApp Business Platform (Cloud API) and the Instagram Messaging API — and our platform app has passed Meta's App Review. We never use QR-code sign-in, browser emulation, session hijacking or third-party "unofficial" gateways. Those are the methods that actually get accounts restricted, because they impersonate a person signing in from an unexpected place; an official API integration does not.
Do you need our password? Can we revoke access?
We never ask for, receive, or store your WhatsApp or Instagram password. Access is granted as a token through Meta's own authorisation screen, and you can revoke it at any time from your account settings or from our dashboard — with no help from us and no effect on the rest of your account. Tokens are stored server-side only, never returned by our APIs, and shown masked in the interface.
So what does put a business account at risk?
Behaviour, not tooling — and it is the same on every platform and every vendor. Sending unsolicited messages in bulk to people who never contacted you generates blocks and reports, which lowers your quality rating and can lead the platform to reduce your messaging limits or restrict the number. Replying to people who messaged you first — how most of our customers use SIPmind — does not carry that risk. If you do run proactive campaigns, they go out only on templates the platform has approved, to contacts who opted in, and you keep the controls.
Is there a trade-off to connecting officially?
One, and it is worth knowing before you start: a number connected to the WhatsApp Business Platform becomes a business number and can no longer be used in the regular WhatsApp app on a phone. Most customers connect a separate number for this reason and keep their personal one untouched. Instagram has no equivalent restriction — you keep using the app exactly as before, and the account must simply be a professional (business or creator) account.
Subprocessors & AI
Who are your subprocessors?
A small, vetted set: OpenAI (US — AI inference), Supabase (EU/US — database & storage), Twilio / Telnyx (telephony), Meta (WhatsApp messaging), Google (mobile push & calendar), Sentry (EU — error monitoring). Each is named in your DPA with the safeguard it provides; we notify you before adding a new subprocessor that handles your data.
Does the AI make clinical or high-stakes decisions? Is there human review?
No. The AI performs reception and scheduling only — no diagnosis, triage, or treatment advice; anything non-routine is escalated to your staff. A human operator can take over any live AI conversation in one click, and co-pilot mode requires an operator to approve a reply before it is sent.
Reliability & incident response
Do you back up data? What about business continuity?
Yes — automated daily database backups, and the platform runs across multiple independent nodes for high availability. Formal RTO/RPO commitments and an uptime SLA are available under an enterprise agreement.
Do you do vulnerability management and penetration testing?
We run automated dependency-vulnerability scanning (weekly) and have performed internal security hardening and testing. Formal third-party penetration testing is planned alongside SOC 2.
What happens if there's a breach?
Encryption, strict per-tenant isolation, role-based access, and configurable retention + auto-deletion of recordings, plus a documented incident process — we notify you promptly so you can meet your own obligations.
Compliance & agreements
How do you handle HIPAA?
We're HIPAA-ready: when a healthcare customer onboards, we provision the environment to the safeguards HIPAA requires and sign a BAA before any protected health information is processed. We don't claim a certification that doesn't exist.
Do you have SOC 2 or ISO 27001?
Not yet — our controls are designed around their objectives, and we pursue formal, independent attestation in step with enterprise requirements. In the meantime we complete your security questionnaire directly, and our core subprocessors (OpenAI, Supabase, Google) hold their own SOC 2 / ISO attestations.
How is payment data handled (PCI)?
Card payments are processed by Stripe (PCI DSS Level 1). We never store or handle raw card data, so card-processing is out of our scope. You can also pay by invoice in your local currency through a certified local partner.
Ownership, deletion & payment
Who owns the data, and can we export or delete it?
You own and control your data; SIPmind is your processor. Retention is configurable with automatic deletion, you can disable storage of sensitive attachments entirely, and export or deletion on request (the right to be forgotten) is part of our standard terms.
Can we pay in our local currency, or not by card?
Yes. You can pay directly by card, or work through a certified local partner who bills you in your region and handles setup — useful where an international card payment isn't an option. For specific procurement, contracting, or on-premise requirements, we also work with you directly.
Talk to us
Security questionnaire, DPA, BAA, or a copy of our security overview — available on request. Contact hello@sipmind.net.