Compliance status
Answering Agent does not hold a SOC 2 report or another security certification yet. We are working toward a SOC 2 examination and will share the report under a confidentiality agreement once it is issued. Until then, we send our current security documentation and answer security questionnaires on request. Email support@answeringagent.com.Where your data lives
Our main subprocessors are Vercel (hosting, file storage, and text AI), PlanetScale on AWS (database), Twilio (phone numbers and texts), ElevenLabs and LiveKit (voice AI), and Resend (email). The DPA has the full list, including background jobs, realtime updates, error tracking, analytics, and billing providers. Data is encrypted in transit and at rest.
AI models and your data
- Answering Agent does not use your data to train AI models.
- Every text AI request goes through Vercel AI Gateway with its zero data retention and no prompt training options turned on. That covers website chat, text, and email replies, call summaries and tasks, and the dashboard assistant.
- Voice calls run on ElevenLabs and LiveKit, which use AI model providers under their own terms.
- An AI app you connect through the MCP server, such as Claude or ChatGPT, follows its own privacy policy, including whether it trains on what it reads.
How long we keep it
To delete a recording, a conversation, or a customer’s data, email support@answeringagent.com. Deletion is handled by our team for each request. A call’s recording in file storage and any copy held by the voice provider are separate steps, and we confirm when each one is done.
Who can see what
- Each person has one of four roles on a team: owner, admin, manager, or user. Owners, admins, and managers with no phone line assignments see the whole team. Others see only the phone lines they are assigned to. See Team members and roles.
- An MCP connection and a webhook each work on one team. An API key reads the team its creator has open in the dashboard, so create keys from a login that belongs to one team.
How integrations authenticate
Each key and each MCP connection acts as the person who created it, with that person’s role and phone lines. The API overview recommends a dedicated integration login so a key keeps working when people leave.