Two questions come up every time. Here are the answers.

The first is some version of "isn't this a bit big brother?" The second is "who can actually see our conversations?" Both deserve a straight answer, so this page is written to be forwarded to whoever asks.

"Isn't this surveillance?"

It's the right question to ask, and the answer is in what the product refuses to do.

Nobody is scored

There is no grade on anyone's calls. No ranking of your team. No coaching report, no performance report, no scorecard going to management about individual people. That isn't a setting we leave switched off - it isn't in the product.

Managers see workload, not verdicts

What a manager sees is what was promised and whether it got done, and which customers need attention. That's the same information the person who took the call sees.

Personal calls are left alone

Conversations that turn out to be personal rather than business get recognized, given minimal handling, and excluded from analysis and from every report. Somebody's call to their doctor doesn't become a record because it happened on a work line.

You choose what's never touched

You can exclude lines, teams, or whole systems. Those conversations are never stored at all - not stored and hidden. Never written.

It's aimed at customers, not employees

The point is knowing what's happening with the people who pay you. Every use case on this site is about a customer, not about watching staff.

Your team should know it's there

We'd rather you tell them, and most businesses find the frontline reaction is positive once they realize it means they stop typing up notes. What it looks like from their side →

"Who can see our conversations?"

Scoped by job

A location manager sees their location. An account manager sees their accounts. Access is enforced rather than being a filter on a view somebody could remove.

Your data is yours alone

Each business's conversations are separated from every other business's. For providers running this for their customers, each of their customers is its own boundary too.

Access is logged

There's a record of who looked at what, and when. It's append-only, which is what makes it worth anything.

What never gets stored

Two things happen before anything is written down, and both of them block the write rather than clean up afterwards.

Card numbers come out. Customers read card details aloud on the phone constantly. Those are removed in the ingestion path, before storage and before anything analyzes the conversation. You'll see a marker where the number was, never the number. The same applies to other sensitive details.

Excluded conversations are never taken. If you've told us not to process something, it isn't processed and isn't stored.

What we don't do with your conversations

We don't train on them. Your customers' conversations produce intelligence for you. They aren't used to improve the product for anybody else. Anything used in developing the platform is irreversibly anonymized first, and the two paths are kept separate on purpose.

We don't keep things forever. How long something is kept depends on what it contains, more sensitive material is kept for less time, and deletion runs automatically rather than when somebody remembers. What we derive from a conversation doesn't outlive the conversation - which is the failure mode that usually catches people out.

We don't act on your behalf. We tell you and your team what's happening. We don't route your escalations, own your tickets, or contact your customers.

Where your data lives

Conversations are processed and stored in the region you choose, and that covers what we derive from them too.

Region is agreed as part of onboarding. If you have a specific obligation, raise it early and you'll get a direct answer about whether we can meet it.

The controls above apply everywhere. More on the setup →

Compliance frameworks

The controls on this page are built against the frameworks our customers and partners operate under.

We'd rather be precise than decorate this page with badges: designing to a framework and holding a formal attestation against it are different things. If you need to know exactly where we stand on a specific framework for a specific deployment, ask and you'll get a straight answer.

If your organization handles protected health information, the deployment requirements are different and worth a direct conversation.

Questions

If you're evaluating us and you have a security questionnaire, a specific control you need evidence for, or something to report, come straight to us at hello@tresic.cloud.

Where to go next