Trust
Security
Version 2026-09-27 · Effective September 27, 2026
Sona carries live phone calls for other people's businesses. This page says, in concrete terms, how we protect what passes through it, and where we have not yet built something you might expect. Found a problem? Go straight to reporting a vulnerability.
How the platform is put together
Calls reach Sona through Twilio, which carries the telephone call and the speech steps of every conversation. The part that decides what to say and which action to take is our own voice service, running on a server we operate. Call records, transcripts, recordings and configuration live in a managed Postgres database and file store (Supabase), and this site and the dashboard are hosted on Vercel. The full list of providers is on our sub-processors page.
Keeping each business's data separate
Sona serves many businesses from one platform, so separation comes first. Every table that holds a business's data carries row-level security keyed to that business, enforced by the database itself, so a query made on behalf of one business cannot read another's rows even if the application asks it to. The dashboard checks the same boundary again in code, and the voice service reads and writes only the data of the business whose number was called.
Encryption
Traffic is encrypted in transit: the dashboard, the telephony webhooks, the live connection that carries each conversation, and our calls to every provider. Data at rest is encrypted by our database and storage provider at the storage level. We do not add a second, per-field layer of encryption on top of that today. Recordings are never publicly addressable: the dashboard fetches each one through a private link that expires after a minute. Where we count or compare callers for analytics, we use a keyed hash of the phone number rather than the number itself.
Checking who is talking to us
Every webhook Twilio sends us is checked against Twilio's signature before we act on it, and so is every event from our payment provider. The dashboard and the voice service authenticate to each other with a shared secret that can be rotated without downtime, because the old and the new one are both accepted for a short overlap. Provider credentials are kept in our hosts' secret configuration, not in code, and the dashboard uses a scoped, revocable telephony key rather than the account master credential.
Access control and accountability
Dashboard users sign in to one business, as an editor who can change settings or a viewer who can only read. Every configuration change is attributed to a person and written to an audit log the business can see. When one of our staff opens the content of a call from our internal console, a record of that access is written to the business's audit log first, and the content is not shown if that record cannot be written.
How we change the platform
Every change to Sona's code is kept in version control, and automated checks run on it: type checks and tests for the dashboard and the voice service, and, whenever the database changes, tests that its row-level security still keeps each business's data separate.
Abuse and toll-fraud limits
Inbound calls cost money on several meters at once, which makes toll fraud a financial attack on our customers. Before a call reaches the AI, the routing layer applies per-caller rate limits and each business's daily spend limit. We can also switch the whole platform to voicemail in an emergency. Businesses can report misuse of a Sona line under our acceptable use policy.
Availability
We do not offer an uptime commitment. The voice service runs as a single always-on deployment today. If it cannot be reached, the phone carrier answers with a short recorded message instead of letting the call ring out; the receptionist does not answer those calls. Every minute, the voice service checks that it can reach its database, the telephony provider and the language-model providers, checks the health of its email sender, and records the results for our team.
Retention and deletion
Recordings are removed from Twilio once they are stored with us, and deleted from our storage automatically when the period each business chooses ends. Other data is kept as our privacy policy describes. We do not yet run an automatic pass that strips card or Social Security numbers from transcripts; the receptionist is instructed never to ask for them and to stop a caller who starts reading one out, and callers should not share them.
Certifications and regulated data
We do not hold a SOC 2 report or any other certification today, and we will not show a badge before a report exists. Nor have we had an independent penetration test yet. Card details never touch our servers: they are entered in our payment provider's own fields. Sona is not designed for protected health information, and we do not offer business associate agreements at this time (see our Terms).
When something goes wrong
If we confirm a security incident affecting a business's data, we notify that business without undue delay, and within 48 hours for customers under our Data Processing Addendum, with what happened, what data was involved, what we have done and what we recommend.
Our knowledge-base crawler
When a business asks Sona to learn from its website, our crawler visits that site. It identifies itself as BizefyBot/1.0, follows the site's robots.txt, and fetches only public HTTPS pages of the site the business named. It sends at most one request per second, reads HTML pages only and at most 2 MB each, stops at the business's page limit, and never signs in or submits a form. If you run a site and want it to stop, disallow BizefyBot in your robots.txt.
Reporting a vulnerability
If you think you have found a security problem in Sona, the dashboard or this site, we want to hear about it. The inbox for reports is still being set up, and its address will be published on this page once it receives mail. We acknowledge reports within three business days, keep you informed while we fix confirmed issues, and credit you if you would like. We will not take action against good-faith research that respects callers' privacy, avoids disrupting the service and gives us reasonable time to fix what you find.