> ## Documentation Index
> Fetch the complete documentation index at: https://docs.answeringagent.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and data handling

> Where Answering Agent stores your data, how long it keeps it, how AI models use it, and how the API, MCP server, and webhooks authenticate.

This page collects the facts a security review usually asks for. The [Privacy Policy](https://answeringagent.com/legal/privacy) and the [Data Processing Agreement](https://answeringagent.com/legal/dpa) are the binding versions. If this page and those disagree, they win.

## Compliance status

Answering Agent does not hold a SOC 2 report or another security certification yet. We are working toward a SOC 2 examination and will share the report under a confidentiality agreement once it is issued. Until then, we send our current security documentation and answer security questionnaires on request. Email [support@answeringagent.com](mailto:support@answeringagent.com).

## Where your data lives

| Data | Where |
| - | - |
| Conversations, transcripts, tasks, contacts, and settings | PlanetScale Postgres, hosted on AWS in us-east-2 (Ohio) |
| Call recordings and attachments | Vercel Blob storage, or ElevenLabs for calls handled through ElevenLabs |
| The application, the API, and the MCP server | Vercel |

Our main subprocessors are Vercel (hosting, file storage, and text AI), PlanetScale on AWS (database), Twilio (phone numbers and texts), ElevenLabs and LiveKit (voice AI), and Resend (email). The [DPA](https://answeringagent.com/legal/dpa) has the full list, including background jobs, realtime updates, error tracking, analytics, and billing providers. Data is encrypted in transit and at rest.

## AI models and your data

* Answering Agent does not use your data to train AI models.
* Every text AI request goes through Vercel AI Gateway with its zero data retention and no prompt training options turned on. That covers website chat, text, and email replies, call summaries and tasks, and the dashboard assistant.
* Voice calls run on ElevenLabs and LiveKit, which use AI model providers under their own terms.
* An AI app you connect through the [MCP server](/mcp-server), such as Claude or ChatGPT, follows its own privacy policy, including whether it trains on what it reads.

## How long we keep it

| Data | Kept for |
| - | - |
| Conversations, transcripts, summaries, and messages | Until deleted. There is no automatic expiry yet. |
| Call recordings | Until deleted. For calls handled through ElevenLabs, ElevenLabs also keeps the recording and transcript. |
| Contacts and tasks | Until deleted. |
| Account information | Length of service plus 1 year |

To delete a recording, a conversation, or a customer's data, email [support@answeringagent.com](mailto:support@answeringagent.com). Deletion is handled by our team for each request. A call's recording in file storage and any copy held by the voice provider are separate steps, and we confirm when each one is done.

## Who can see what

* Each person has one of four roles on a team: owner, admin, manager, or user. Owners, admins, and managers with no phone line assignments see the whole team. Others see only the phone lines they are assigned to. See [Team members and roles](/user-roles).
* An MCP connection and a webhook each work on one team. An API key reads the team its creator has open in the dashboard, so create keys from a login that belongs to one team.

## How integrations authenticate

| Integration | How it signs in | What it can do |
| - | - | - |
| [Customer API](/api/overview) | An `X-API-KEY` header. Owners and admins create keys in **Settings → API Keys**. | Read the team's data, change a task's status or assignee, and add task notes. Keys have no scopes and do not expire. Revoke a key to stop it. |
| [MCP server](/mcp-server) | OAuth with your dashboard login. The AI app never sees your password. | Read the team's data and AI settings, change a task's status or assignee, and add task notes. It cannot change settings or message customers. |
| [Webhooks](/webhooks) | Each request carries a shared secret in the `X-Answering-Agent-Secret` header. The body is not signed. | Send each new task to one HTTPS address per team. |

Each key and each MCP connection acts as the person who created it, with that person's role and phone lines. The [API overview](/api/overview#authenticate) recommends a dedicated integration login so a key keeps working when people leave.

## Report a security issue

Email [support@answeringagent.com](mailto:support@answeringagent.com). Under the DPA, we notify affected customers without undue delay after we learn of a breach.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.