The short version of the security page, written from what the product does today rather than from a roadmap. Every line here is something you can check from inside your own workspace.
Your workspace holds what you put in it and what it produces: the workflows and channels you author and the rules they run on; the conversations, drafts, approvals and refusals they generate; a consent record per person, per channel; and your settings, including your timezone, your retention period and your transfer number. If you imported your first configuration from your website or Google profile, each field records where it came from, and fields with no source were left blank rather than guessed.
Customer-facing conversations, on the web widget, SMS, WhatsApp and voice, are answered from your approved rules through one resolver, with no model call. A conversation is never sent to a model provider. Your data is never sold and never used to train a shared model.
The platform runs at app.feerasta.ai on a server in Germany, and the website is delivered by Cloudflare. Every provider that processes data on our behalf, with what it does and where, is on the subprocessors page, which is updated before a new one is added. Inside the product, a provider disclosure shows which of them your own workspace actually uses.
Where residency or regulation rules out a shared platform, Feerasta Sovereign runs the same workflows on infrastructure you control.
The whole workspace, as JSON, from inside the product, whenever you want it, with secrets redacted. The audit log can be exported on its own. Neither needs a ticket or a wait on us.
On the first turn of a call or text, the agent says it is AI and names your business. On text, the line repeats on the first reply to a sender every 30 days. You can turn it off; if you do, the liability is yours. How and where AI is used across the product is written up on the AI transparency page.
Consent is recorded per person, per channel. STOP on any channel revokes every channel, HELP is answered, and both are recognised as the first word of a message in English and French. A message with no consent record is refused, and the refusal is logged, so there is a trace of what did not send as well as what did. Every outbound channel starts switched off, and a channel with a failing backtest of your own history cannot be switched on.
Every approval, rejection and refused send is on the audit log. Approvals are made inside the product by an owner or an approver; a member can be invited by email but cannot approve, only an owner manages the team, and the last owner cannot be demoted or removed. You can export the log whenever you want. How that is enforced →
Model-backed drafting, the books, reports and replies that wait for your approval, runs on a model key you bring, stored encrypted on your workspace. With no key, that drafting stays off and the product says so. The providers we work with are named on the subprocessors page: Anthropic, OpenAI and NVIDIA for models, ElevenLabs and Twilio for voice and messaging. Which of them your workspace uses is shown inside the product.
Three check-in mails, on day 7, day 14 and then monthly, signed by Meer Feerasta. Reply to any of them. Support hours, response times and how to report a security problem are on the security page.
No customer counts, no savings figures, no accuracy percentage. What we publish instead is the trace, the refusal count and the audit trail, on your own conversations. If a document you need is not on this page, ask and we will send it, or tell you plainly that we do not have it.
Last updated 2 September 2026. Questions: hello@feerasta.ai.