TelonicDocs
English

Security and data protection

Deployment separation

How your deployment and data are kept apart from every other customer's, the levels of separation available, and how separation works inside your own organisation.

On this page
  1. Four levels of separation
  2. What reaches Telonic from your own environment
  3. Separating parts of your own organisation
  4. Test and live environments
  5. Choosing a level of separation
  6. Moving to a different level
  7. In practice
  8. What your team controls
  9. Related

Your customers' data should never be reachable by another organisation, and a problem in someone else's deployment should never become yours. Telonic keeps each customer's deployment and data separate from every other customer's. You choose how strong that separation is, from logical separation in regional hosting to a deployment that runs entirely inside your own environment. This page explains each level, how separation works between parts of your own organisation, and how test and live environments are kept apart.

Four levels of separation

LevelHow it worksHosting options
Logical separation (the default in regional hosting)Your deployment runs on cloud infrastructure Telonic operates in the UAE or in Saudi Arabia. Your data, configuration and agents are bound to your deployment, and access controls stop any other customer's users, agents or processes from reaching themUAE region, Saudi Arabian region
Dedicated environmentYour deployment runs on computing and storage used only by you, within Telonic's regional hostingUAE region, Saudi Arabian region
Your own cloud accountEvery component runs inside a cloud account your organisation ownsYour own cloud account on Microsoft Azure, AWS, Google Cloud or Core42
Your own premisesEvery component runs on infrastructure in your own data centre. Language models are open-weight models (models whose trained parameters are published, so they can run on your own hardware), and speech models are self-hosted. Computing capacity is sized with you during implementationYour own premises

In every level, your data is encrypted at rest with AES-256 (the Advanced Encryption Standard, using 256-bit keys), and your team reaches it only through your own sign-in and roles. See Encryption and Access control and single sign-on.

What reaches Telonic from your own environment

In your own cloud account and on your own premises, every component runs inside your environment. Only operational health signals, containing no customer data, are sent to Telonic, so that our engineers can see whether the deployment is running properly. You can switch these signals off. Access by Telonic engineers to your environment needs your approval each time.

Separating parts of your own organisation

One contract can serve several parts of your business without mixing them. Separate agents, data and reporting are set up for each business unit or brand, such as a residential and a commercial division, or two hotel brands. Roles can be limited to one unit, so a team sees only its own conversations and reports.

Where customers deal with more than one unit, how the customer record is shared between units is agreed with you during implementation. Your legal team decides what your data policy allows.

Test and live environments

Every deployment has a test environment separate from the live one. Changes to agents, limits and connections are made and tested there before any customer sees them.

Test conversations use test numbers and test accounts. Live customer data is not copied into the test environment unless you agree, and then only with personal information redacted. See How changes go live.

Choosing a level of separation

Most organisations start from their own data classification policy.

  1. Does your policy require physically separate infrastructure for conversation data? If it accepts logically separated cloud infrastructure, logical separation applies, with encryption and role-based access. If it requires infrastructure used only by you, choose a dedicated environment.
  2. Must customer data stay in infrastructure you control? Choose your own cloud account or your own premises.
  3. Does a regulator or procurement rule name the infrastructure you may use? Your own cloud account or your own premises runs the deployment inside infrastructure you have already approved.

Every product capability is included at every package size. Your hosting option, a dedicated environment if you choose one, and Meta's charges for marketing templates are reflected in your quote. See How pricing works.

Moving to a different level

You can move between hosting options after go-live (the point at which the agent starts handling real customers), for example from logical separation in the UAE region to your own cloud account. The move is a migration agreed and scheduled with you. Data is moved encrypted and never leaves the countries you have permitted.

In practice

Qamar Stays, a hotel group with two brands, chooses its separation.

  1. Its data classification policy treats guest conversations as confidential, and does not require physically separate infrastructure. The group chooses logical separation in the Saudi Arabian region.
  2. Each brand has its own agents, its own data and its own reporting under one contract. Front office teams see only their own brand's conversations.
  3. The group agrees that a guest's record is visible to both brands' loyalty team, and nowhere else.
  4. A change to the premium brand's late checkout rule is made and tested in the test environment, then released to live.
  5. Two years later, a new group security policy requires customer data to stay in infrastructure the group controls. The deployment moves to the group's own cloud account through a migration agreed and scheduled with its IT team.

What your team controls

  • The level of separation, and moving between levels.
  • The business units and brands, and which roles can see each one.
  • How the customer record is shared between units.
  • In your own environment, the operational health signals, and approval of engineer access.

Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.