Skip to content
Security & trust

Your data stays yours.

AI you can put in front of patients, clients, and the books, without giving up control of your data, your brand, or the decision.

The rules we run on

Six things we promise, on every line.

Never sold, never trained on

Your data is never sold, and not used to train our models.

Provider training is disabled where the provider offers that setting

Each AI provider is used with training on customer data disabled where the provider offers that setting (see /subprocessors).

Human-checked

A person reviews what the AI does.

You stay in control

Nothing sends, pays, or commits on your behalf without your say-so.

A full audit trail

Every action, and the reasoning behind it, logged and reviewable any time.

Tested before it's live

We test it against your real calls and records before it goes live.

On your own ground, if needed

For regulated or sensitive work, the AI can run on hardware you control.

How your data is handled

Where it lives, who touches it, how long.

The short version is on the trust page.

Where it runs
One server in Germany (Hetzner, Falkenstein). Canadian and US regions are on the roadmap, not available today.
The detail

The platform runs on one server in Germany (Hetzner, Falkenstein) and the website is delivered by Cloudflare. Canadian and US regions are on the roadmap, not available today. On a Sovereign deployment the storage is yours.

In transit & at rest
Everything is encrypted in transit (TLS). The application server's disk is not full-disk encrypted today.
The detail

Everything is encrypted in transit (TLS). At rest: server-side encryption of stored secrets and backups. The application server's disk is not full-disk encrypted today; we say so rather than round it up to "encrypted at rest".

In processing
The platform's rules-based web, messaging and Twilio voice workflows answer through one shared resolver, with no model call.
Model-backed drafting and natural voice are separate paths

The platform's rules-based web, messaging and Twilio voice workflows answer through one shared resolver, with no model call. Model-backed drafting and ElevenLabs natural-voice agents are separate paths. The providers used by your workspace are disclosed in the product.

Sub-processors
A named, limited set of providers. Our data processing agreement is a template, signed on request.
The detail

We use a named, limited set of providers (hosting, voice, models, payments). The full list is published, with what each one does and where it processes, and the product shows you which of them your own workspace uses. Our data processing agreement is a template, signed on request.

Your own model key
Model-backed drafting runs on a model key you bring, or on no key at all, in which case that drafting stays off.
The detail

Model-backed drafting runs on a model key you bring, stored encrypted on your workspace, or on no key at all, in which case that drafting stays off and the product says so. The rules-based resolver makes no model call. Natural-voice agents use a separate provider path.

Roles and approvals
A draft is approved by an owner or an approver; a member cannot approve.
The detail

Owner, approver and member roles, invited by email from inside the product. A draft is approved by an owner or an approver; a member cannot approve. Only an owner manages the team, and the last owner cannot be demoted or removed.

Consent ledger
A message with no consent record is refused and logged rather than sent.
The detail

Consent is recorded per person, per channel. STOP on any channel revokes every channel, HELP is answered, and a message with no consent record is refused and logged rather than sent. Every outbound channel starts switched off.

Retention
You set a retention period for eligible workspace records.
Consent, opt-out and audit records are retained separately

You set a retention period for eligible workspace records. Consent records, opt-outs and audit records are retained separately to preserve the record of permissions and decisions. See the trust page for account-deletion details.

Export and deletion
Export everything as JSON from inside the product at any time, secrets redacted.
Deletion runs after a 30-day window

Export everything as JSON from inside the product at any time, secrets redacted. Deletion is scheduled from inside the product after you have taken an export, and runs after a 30-day window in which you can cancel it.

Audit export
Every approval, rejection and refused send is on the audit log, and you can export that log.
Your timezone
Every workflow runs on your timezone.
The detail

Every workflow runs on your timezone. Business hours and schedules are read in your local time, not ours.

Your customers' data
Call recordings, bookings, and records are yours.
The detail

Call recordings, bookings, and records are yours. They are not pooled, not resold, and not used to improve a shared model.

AI disclosure
Our agents say they are AI and name your business. You can turn the line off, at your own liability.
The detail

On the first turn of a call or text our agents say they are AI and name your business, in line with the EU AI Act's transparency rule (Article 50) and good practice everywhere. You can turn the line off, at your own liability.

One resolver, three channels In the platform's rules-based workflow, a message from the web widget, SMS, WhatsApp or the Twilio voice pipeline reaches one deterministic resolver that makes no model call. The resolver checks safety first, then the active workflow, then the approved FAQ, then a fallback that takes a contact. A safety hit is handed to a person, an ordinary reply is queued as a draft for an approver, and the answer returns on the same thread. THREE CHANNELS WHAT COMES BACK SAFETY FIRST DRAFT FIRST ANSWER SAME THREAD Web widget key in the page source SMS / WhatsApp one thread per person Phone call by number dialled One resolver automation/respond.mjs · no model call 0 · Safety, checked first human request · complaint · regulated advice 1 · Your active workflow rules you can read · every run leaves a trace 2 · Your approved FAQ the same answer every time 3 · Fallback takes a contact, never invents one Handed to a person on every channel Draft queue until your approver arms it Answer, same thread same words every time LEGEND the one decision path returns to the customer held until a person approves

Every channel lands in the same resolver. Safety is checked before anything a client can configure.

Scroll the diagram sideways to see the whole path.

Support and status

How to reach us, and how fast.

These are commitments, not aspirations.

Support hours
Monday to Friday, 9am to 6pm Eastern.
Outside those hours

Monday to Friday, 9am to 6pm Eastern. Anything that has stopped a client's business working is handled outside those hours too.

First response
Within one business day for a normal request. Within four hours during support hours if something is down or a customer-facing agent is answering wrongly.
How to reach us
Email hello@feerasta.ai.
Larger deployments

Clients on a larger deployment get a named contact and a direct number as part of the engagement.

Escalation
One escalation step: the founder.
Security reports
Email security@feerasta.ai. We acknowledge within two business days. Details and what to expect are at /.well-known/security.txt.
Live status
The website, the platform and the public demos are monitored every five minutes.
The status page and the public checks

The website, the platform and the public demos are monitored every five minutes. What is covered, how incidents are communicated and how to report one are on the status page; the live checks are public at stats.uptimerobot.com. You do not have to ask us whether something is down.

Uptime SLA
We do not print a percentage we cannot yet show the history for.
SLA terms are published on request

Business tier SLA terms are published on request until the status page carries ninety days of measured history. We do not print a percentage we cannot yet show the history for.

We would rather commit to numbers we control than to one we cannot enforce against our own providers. Larger deployments can have availability and response terms written into the statement of work.

Compliance posture

Controls your team can review.

Specific requirements are assessed during scoping.

GDPR & RGPD aligned PIPEDA (Canada) CCPA (California) EU AI Act Article 50 disclosure Zero data resale No model training on your data On-prem option for regulated work Human-in-the-loop by default

We state what we actually do, not badges we haven't earned.

The on-premise option

For health, legal, and financial work where data sensitivity is highest, the on-premise Sovereign option keeps everything inside your own walls.

For regulated businesses

Health, legal, and finance: the sensitive ones.

You get the strictest setup: human review on everything sensitive, the on-prem option, and AI that captures and routes but never advises.

The security questionnaire, answered.

The CAIQ v4 domains and a SIG Lite-style short set, 96 answers marked Yes, No, Partial or Not applicable with the evidence for each. Including the ones where the answer is no.

Is data encrypted in transit and at rest?
In transit: yes, TLS everywhere. At rest: server-side encryption of stored secrets and backups. The application server's disk is not full-disk encrypted today.
Is our data used to train AI models?
No. Not ours, not a shared model, not a provider's. It is not pooled with other clients and never resold.
Can the AI act without a human approving it?
No. Anything that pays, posts or sends is drafted for a named person to approve.
Where draft-only is enforced

Anything that pays, posts or sends is drafted for a named person to approve, and draft-only is enforced in the server and the agent container, not only in the prompt.

What happens when something goes wrong?
Detection, classification, containment, the 72-hour breach notice and the nightly, content-verified, encrypted-offsite backups with a restore drill are on the incident response and backups page.

All 96 answers, by domain, with a CSV you can paste into your tool → Anything not answered there, ask and we will answer it in writing, including where the honest answer is that we don't do it yet. Send your requirements → Last reviewed 2 September 2026.

Have a security question? Ask it directly.

Send us your requirements, your industry's rules, or your IT team's checklist.

Start free → Talk to us