Security & Compliance

How we protect your data — and the agreements we sign.

SIPmind handles your customers' calls, messages, and records. We treat that data as yours, not ours. This page describes how it is protected, where it can live, and the contracts that put it in writing. Where a capability is provisioned per engagement rather than enabled by default, we say so.

SIPmind is built and operated by Techdab LLC, a United States company. It is available directly, or through certified local partners and integrators who can handle billing, deployment, and specific compliance requirements in your region.

Your data stays yours
Processor model · DPA with every customer
You choose where it lives
Regional hosting or fully self-hosted
Healthcare-ready
We sign a BAA before any PHI flows

Your data is yours — we are your processor

You remain the owner and controller of your data. SIPmind processes it only on your instruction, for the purpose of running your service — never for our own purposes, and never to train models for anyone else. We sign a Data Processing Agreement (DPA) with every customer that puts this in writing, including the list of subprocessors, security obligations, and data-deletion terms. We do not sell your data.

Encryption

All data is encrypted in transit (TLS 1.2+) and at rest. API keys and credentials are stored server-side only, never exposed to the browser or returned by our APIs, and shown masked in the interface.

Strict tenant isolation

Every account's data is scoped to its tenant in application code on every request — one customer's account cannot read, write, or even see another's. Row-level security is enabled at the database layer as an additional backstop.

Access control & auditability

Role-based access (administrator vs. operator) with least-privilege defaults: operators see conversations and leads, not settings, keys, or billing. Sensitive actions are logged, and device access (mobile / softphone) can be revoked instantly.

You choose where your data lives

This is where SIPmind goes further than a typical cloud product. You can:

We adapt to your local data-protection requirements, localize storage where your jurisdiction mandates it, and sign the agreements your regulator expects. For data that does cross a border (for example, to an AI processor), we do so only on a lawful basis you control, and we name every recipient in your DPA.

Healthcare: HIPAA-ready

For healthcare customers, "HIPAA-ready" means a specific, provisioned setup. When you onboard, we provision your environment to meet the administrative, physical, and technical safeguards that HIPAA requires, sign a Business Associate Agreement (BAA), and put that protected setup in place before any protected health information is processed. It is built on HIPAA-eligible infrastructure.

There is no HIPAA "certification" to hold, so we claim none. What we provide is configured per practice — a signed BAA, an environment set to the required safeguards, and a clear division of responsibilities — put in place as soon as a healthcare customer comes on board.

Subprocessors, transparently

We rely on a small, vetted set of subprocessors for AI processing, database, and hosting. The current list — and the safeguards each one provides — is named in your DPA and available on request. We notify you before adding a new subprocessor that handles your data.

Retention & deletion you control

You decide how long data is kept. Call recordings, message attachments, and records have configurable retention with automatic deletion, and you can disable storage of sensitive attachments entirely. Deletion and export on request are part of our standard terms.

Incident response

We operate a documented detection and incident-response process and continuously monitor our systems. If an incident affects your data, we notify you promptly with the facts you need to meet your own obligations to your customers and your regulator.

Aligned with leading frameworks

Our security controls are designed around the objectives of SOC 2 and ISO 27001, and — for healthcare — HIPAA. We pursue formal, independent attestation in step with enterprise customer requirements. If you have a security questionnaire or need a specific control mapping, send it over — we answer them directly.

The agreements we sign

Trust should be in writing, not just on a page. With each customer we put in place:

Security questionnaire

The questions a security or procurement team usually asks — answered directly, including where a control is on our roadmap rather than in place today. Need a formal CAIQ / SIG or your own questionnaire completed? Send it to hello@sipmind.net and we'll return it directly.

Data & encryption

Is data encrypted?

Yes — in transit (TLS 1.2+) and at rest. API keys and credentials are stored server-side only, never returned by our APIs or exposed to the browser, and shown masked in the interface.

Where does our data live?

By default our platform database is in the EU. Where your jurisdiction requires the primary database to be in-country, we provision a dedicated in-region database as part of the engagement, and your telephony can run on your own infrastructure. The AI processor (OpenAI) is in the US — that step always crosses a border, on a lawful basis you control and named in your DPA.

Do you use our data to train AI?

No. We process your data only to run your service — never to train models for anyone else — and we never sell it. On our AI provider's API, customer data is not used to train their models, and we pursue Zero Data Retention on eligible endpoints for regulated workloads.

What is sent to the AI processor in another country?

Only the conversation text needed to answer, on a lawful basis you control (your customers' consent — we give you the wording). Sensitive records — for example medical results — stay in your own system; we don't process them. Every recipient is named in your DPA.

Access, authentication & isolation

How is one customer's data kept separate from another's?

Every account's data is scoped to its tenant in application code on every request — one customer cannot read, write, or even see another's. Row-level security is enabled at the database layer as an additional backstop.

How do users authenticate? Do you support MFA / SSO?

Dashboard and mobile logins use passwords that are stored hashed (never in plaintext); sessions are signed, expiring tokens; per-tenant API keys are stored as SHA-256 hashes. Access is role-based (administrator vs. operator, least-privilege), and device access can be revoked instantly. Multi-factor authentication and SSO/SAML are on our roadmap and are not enabled today.

Are administrator and sensitive actions logged?

Sensitive actions are logged, and we continuously monitor our systems with error tracking that is configured to exclude PII and secrets (frame locals and personal data are not sent to our monitoring provider).

Messaging channels & account safety

Can connecting SIPmind get our WhatsApp number or Instagram account banned?

No. We connect only through Meta's official interfaces — the WhatsApp Business Platform (Cloud API) and the Instagram Messaging API — and our platform app has passed Meta's App Review. We never use QR-code sign-in, browser emulation, session hijacking or third-party "unofficial" gateways. Those are the methods that actually get accounts restricted, because they impersonate a person signing in from an unexpected place; an official API integration does not.

Do you need our password? Can we revoke access?

We never ask for, receive, or store your WhatsApp or Instagram password. Access is granted as a token through Meta's own authorisation screen, and you can revoke it at any time from your account settings or from our dashboard — with no help from us and no effect on the rest of your account. Tokens are stored server-side only, never returned by our APIs, and shown masked in the interface.

So what does put a business account at risk?

Behaviour, not tooling — and it is the same on every platform and every vendor. Sending unsolicited messages in bulk to people who never contacted you generates blocks and reports, which lowers your quality rating and can lead the platform to reduce your messaging limits or restrict the number. Replying to people who messaged you first — how most of our customers use SIPmind — does not carry that risk. If you do run proactive campaigns, they go out only on templates the platform has approved, to contacts who opted in, and you keep the controls.

Is there a trade-off to connecting officially?

One, and it is worth knowing before you start: a number connected to the WhatsApp Business Platform becomes a business number and can no longer be used in the regular WhatsApp app on a phone. Most customers connect a separate number for this reason and keep their personal one untouched. Instagram has no equivalent restriction — you keep using the app exactly as before, and the account must simply be a professional (business or creator) account.

Subprocessors & AI

Who are your subprocessors?

A small, vetted set: OpenAI (US — AI inference), Supabase (EU/US — database & storage), Twilio / Telnyx (telephony), Meta (WhatsApp messaging), Google (mobile push & calendar), Sentry (EU — error monitoring). Each is named in your DPA with the safeguard it provides; we notify you before adding a new subprocessor that handles your data.

Does the AI make clinical or high-stakes decisions? Is there human review?

No. The AI performs reception and scheduling only — no diagnosis, triage, or treatment advice; anything non-routine is escalated to your staff. A human operator can take over any live AI conversation in one click, and co-pilot mode requires an operator to approve a reply before it is sent.

Reliability & incident response

Do you back up data? What about business continuity?

Yes — automated daily database backups, and the platform runs across multiple independent nodes for high availability. Formal RTO/RPO commitments and an uptime SLA are available under an enterprise agreement.

Do you do vulnerability management and penetration testing?

We run automated dependency-vulnerability scanning (weekly) and have performed internal security hardening and testing. Formal third-party penetration testing is planned alongside SOC 2.

What happens if there's a breach?

Encryption, strict per-tenant isolation, role-based access, and configurable retention + auto-deletion of recordings, plus a documented incident process — we notify you promptly so you can meet your own obligations.

Compliance & agreements

How do you handle HIPAA?

We're HIPAA-ready: when a healthcare customer onboards, we provision the environment to the safeguards HIPAA requires and sign a BAA before any protected health information is processed. We don't claim a certification that doesn't exist.

Do you have SOC 2 or ISO 27001?

Not yet — our controls are designed around their objectives, and we pursue formal, independent attestation in step with enterprise requirements. In the meantime we complete your security questionnaire directly, and our core subprocessors (OpenAI, Supabase, Google) hold their own SOC 2 / ISO attestations.

How is payment data handled (PCI)?

Card payments are processed by Stripe (PCI DSS Level 1). We never store or handle raw card data, so card-processing is out of our scope. You can also pay by invoice in your local currency through a certified local partner.

Ownership, deletion & payment

Who owns the data, and can we export or delete it?

You own and control your data; SIPmind is your processor. Retention is configurable with automatic deletion, you can disable storage of sensitive attachments entirely, and export or deletion on request (the right to be forgotten) is part of our standard terms.

Can we pay in our local currency, or not by card?

Yes. You can pay directly by card, or work through a certified local partner who bills you in your region and handles setup — useful where an international card payment isn't an option. For specific procurement, contracting, or on-premise requirements, we also work with you directly.

Talk to us

Security questionnaire, DPA, BAA, or a copy of our security overview — available on request. Contact hello@sipmind.net.