Security and data protection
Security and data protection: overview
How Telonic protects your customers' data, the control behind each part of the security model, and how your security team can review it.
On this page
- How the controls fit together
- The controls at a glance
- Where your data is processed and stored
- What leaves your deployment, and in what form
- Who can reach your data
- How long data is kept, and how it is deleted
- When something goes wrong
- How the product is built and changed
- How the agent behaves with your customers
- How your security team can review Telonic
- In practice
- What your team controls
- Related
Your customers' conversations carry the information they trust you with most: identity numbers, payment details, claims, bookings and complaints. Before any of it reaches Telonic, your security team needs to know where it goes, who can reach it, what protects it and what happens if something goes wrong. This page summarises the security model and links to the page that sets out each control in detail. Every linked page gives the plain explanation first and the technical specifics after it.
How the controls fit together
The security model works in layers, from the outside in. Your deployment runs in the region you choose, and inside it your data is kept separate from every other customer's, encrypted, and reachable only by the people and agents whose role requires it. Personal information is redacted before any data leaves for anywhere other than your own systems and your own customers. Around every layer sit the processes that keep the controls working: secure development, testing before release, monitoring and incident response.
The controls at a glance
| Control | What it means for you | Detail |
|---|---|---|
| Hosting and data residency | Your deployment runs in a UAE region, a Saudi Arabian region, your own cloud account or your own premises. All processing for your deployment runs in the region you choose, unless you explicitly choose a provider outside it for the language model (the AI model that understands the conversation and decides the reply) | Hosting and data residency |
| Data flow | Each step of a conversation is documented: where it enters, which provider handles each part, and what is stored | How data flows through a conversation |
| Redaction | Personal information is redacted before data leaves your deployment for anywhere other than your own systems and your own customers. Reports and exports are redacted by default | Personal information redaction |
| Storage and retention | Nothing is stored without your permission. You set how long each kind of content is kept | Storage, retention and deletion |
| Encryption | Connections are encrypted with TLS (Transport Layer Security, the standard encryption for data sent over networks) 1.2 or higher, call audio with SRTP (Secure Real-time Transport Protocol) by default, and stored data with AES-256 (the Advanced Encryption Standard, using 256-bit keys) | Encryption |
| Access | Your team signs in through your own identity provider (the system that manages your staff's logins), with multi-factor authentication (a second check beyond a password). Each person and each agent has only the access its role needs, and access and changes are logged | Access control and single sign-on |
| Separation | Your data is separated logically from other customers' data by default, and a dedicated environment is available | Deployment separation |
| Sub-processors | The providers that process data for your deployment on Telonic's behalf are listed in your data processing terms (the part of your agreement that covers personal data). You get 30 days' notice of any change, with the right to object | Sub-processors |
| Incident response | A defined process. Personal data breaches are notified to your named contacts without undue delay, and within 24 hours of becoming aware of a breach affecting your data | Incident response |
| Secure development | Every change is reviewed and tested before release. Any change of model or provider needs your approval first | Secure development and testing |
| Responsible use of AI | The agent says it is an AI agent, answers from your approved sources, and leaves the decisions that belong to people with your team | Responsible use of AI |
Where your data is processed and stored
You choose one of four hosting options: a UAE region, a Saudi Arabian region, your own cloud account or your own premises. Regional hosting uses major cloud providers' data centres in the UAE and in Saudi Arabia, and the provider and region are named in your agreement. For your own cloud account, Microsoft Azure, AWS, Google Cloud and Core42 are supported.
All processing for your deployment runs in the region you choose, unless you explicitly choose a language model provider outside it. Speech recognition (turning speech into text) and voice synthesis (speaking the reply) always run in your chosen region, and images and documents your customers send are read by a model running there too. Backups and disaster recovery copies are encrypted and stay in the same country as your deployment.
Your customers reach you through networks you already use. Your carrier carries calls under your contract with it, and Meta receives, processes and briefly stores WhatsApp messages on its own infrastructure before they reach your deployment. The full path is on How data flows through a conversation.
What leaves your deployment, and in what form
Your own systems and your own customers receive what they need: a lookup carries the booking reference, and a reply carries the customer's name. For every other destination, personal information is redacted first. Redaction covers names in Arabic and Latin script, phone numbers, email addresses, national identity numbers (including Emirates ID and Iqama numbers), passport numbers, payment card numbers, bank account numbers and IBANs (international bank account numbers), dates of birth and street addresses.
If you choose a language model outside your region, it receives text in which each piece of personal information has been replaced with a placeholder. The real values are restored in the reply inside your deployment. Reports and exports are redacted by default.
Who can reach your data
Your team signs in through single sign-on (one work account for all your systems) with your own identity provider, using multi-factor authentication. Each person and each agent has only the access its role needs, and every access and change is logged.
Access by Telonic staff is limited to named engineers, working from the UAE or from the country you choose, for a limited time, and every access is logged. In your own cloud account or on your own premises, each access needs your approval.
How long data is kept, and how it is deleted
Nothing is stored without your permission, and you set how long each kind of content is kept. Where your policy does not allow conversation content to be kept, zero content retention is configured during implementation, and a content-free audit record of actions, sources, triggers and outcomes is still kept for the period you set. When your contract ends, your data is returned to you in a standard format and then deleted, or deleted without return if you prefer, and you receive written confirmation. See Storage, retention and deletion.
When something goes wrong
Telonic runs a defined incident response process: detect, triage by severity, contain, notify, remediate and review. Personal data breaches are notified to your named contacts without undue delay, and within 24 hours of becoming aware of a breach affecting your data, with updates as the investigation continues.
Critical incidents are covered 24 hours a day, seven days a week. Provider failover, which switches to another approved provider in your region if one has an outage, is configured during implementation. See Incident response.
How the product is built and changed
Every change is reviewed and tested before release, in a test environment kept separate from your live one. Agent changes are tested against conversations drawn from your industry, and no change of model or provider reaches your customers without your approval. Independent testers carry out penetration testing (an authorised, simulated attack to find weaknesses) at least once a year and after major changes. See Secure development and testing.
How the agent behaves with your customers
The agent tells customers it is an AI agent and offers them a person. It answers from your approved sources, and decisions that belong to people, such as approving a claim or agreeing a refund outside policy, stay with your team. See Responsible use of AI.
How your security team can review Telonic
Ask your Telonic contact for the security pack. It is shared under a non-disclosure agreement (NDA) and includes an architecture description and data flow diagrams for your hosting option, the list of sub-processors and the data processing terms. We complete your security questionnaire in whatever format you use, and our engineers meet your security team to walk through each control.
Starting the review early, alongside the business discussion, keeps it from holding up a decision later. If your procurement process lists specific certifications or accreditations as requirements, raise them in the first conversation, so both teams know from the start how they will be addressed.
In practice
Wadi Assurance, a UAE insurer, reviews Telonic before deploying on its claims line.
- In the second week of discussions, Hamza, its head of information security, asks for the security pack. Telonic sends it once both sides have signed an NDA.
- Hamza's team sends its standard questionnaire. Telonic's engineers complete it and return it with the architecture for the UAE region option.
- In the walkthrough, the team asks what leaves the region. Nothing leaves for a model provider, because Wadi Assurance keeps every provider in-region. Monthly exports to its analytics team are redacted by default.
- The data protection officer sets retention: call recordings for the period the claims policy requires, and transcripts and summaries for the life of the policy plus the period she specifies.
- Staff sign in through the insurer's own identity provider. Claims handlers see conversations, and only the compliance team sees the audit log.
- The hosting option, the providers and the named contacts for incident notification are recorded in the agreement.
What your team controls
- The hosting option and region.
- Whether a language model outside your region may be used at all.
- Whether each kind of content is stored, and for how long.
- Who in your organisation can see what, through roles.
- Approval of each Telonic engineer access in your own cloud account or on your own premises.
- Approval of any change of model or provider before it goes live.
- In your own cloud account, the encryption keys.
- The named contacts who receive incident notifications.
Related
- Hosting and data residencySecurity and data protection
- How data flows through a conversationSecurity and data protection
- Personal information redactionSecurity and data protection
- Access control and single sign-onSecurity and data protection
- Contracts and data processing termsLegal and compliance
Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.