Skip to content

Security and control

Security and control for Havio AI receptionist calls.

Havio documents how approved knowledge, human escalation, recordings and transcripts, retention, subprocessors, incident response, and call review are handled.

Approved knowledge

Agents answer from approved services, policies, and FAQs, then fall back when confidence or policy boundaries are not met.

Human escalation

Urgent, sensitive, uncertain, or high-value calls route to people with caller context and transcript-ready notes.

Data handling

Publish clear policies for recordings, transcripts, retention, deletion, subprocessors, and regions before regulated buyers ask.

Audit and review

Every handled call is reviewable so teams can tune prompts, routing, and knowledge over time.

Security controls

Concrete checks for procurement.

This matrix keeps the public claims narrow. It shows what buyers should verify before enabling recordings, integrations, regulated workflows, or enterprise access requirements.

Control
Public state
Buyer check
Encryption in transit
Required for Havio web traffic and supported connected services.
Confirm any telephony, CRM, or webhook destination that sits outside the Havio app path.
Encryption at rest
Expected for hosted application data and storage providers used in the workflow.
Confirm recording, transcript, and connected-system storage settings before regulated launches.
Admin access
Workspace access should use least-privilege roles and named owners.
Enterprise buyers should request access review cadence, admin list, and offboarding process.
MFA and SSO
MFA is expected for administrative accounts. SSO availability depends on the signed plan and provider stack.
Do not assume SSO is included in self-serve SMB plans; confirm during procurement.
Audit logging
Operational review relies on call records, workflow outcomes, integration events, and support history where available.
Define which logs are exported, retained, and reviewed before live caller traffic is routed.
Backups and recovery
Provider-level backup and recovery depend on the hosted services and connected systems in the deployment.
Critical workflows should document rollback, forwarding pause, data export, and restore expectations.
Vendor review
Subprocessors should be reviewed before sensitive data, recordings, or regulated workflows are enabled.
Use the subprocessor and DPA pages to verify purpose, data type, region, and contract path.
Certification status
No public SOC 2 or ISO certification claim is made on this site.
Buyers that require formal attestations should request the available security package before procurement.

Trust center

What buyers can verify before launch.

Voice AI touches callers, phone numbers, transcripts, routing, and business systems. This page makes the control model inspectable before a demo.

Area
Havio control
Where to verify
Recordings and transcripts
Decide during setup whether calls are recorded, how transcripts are stored, who can review them, and how long they remain available.
Privacy policy, DPA, retention terms
Approved knowledge
The agent answers from approved services, policies, FAQs, prices, locations, and routing rules instead of improvising.
AI policy, launch checklist, review loop
Human fallback
Urgent, sensitive, uncertain, angry, regulated, or high-value calls transfer or create a callback with context.
AI disclosure policy, acceptable use, SLA
Subprocessors
Buyers can see which infrastructure, communications, analytics, and support providers may process customer workflow data.
Subprocessors page and DPA
Regions and residency
Market, telephony, and customer data requirements are confirmed before regulated or cross-border deployments.
DPA, security response, customer agreement
Incident response
Security issues need a clear report path, triage owner, severity handling, and customer notification expectation.
Security response policy

Trust starts with plain answers: disclosure options, recording and transcript handling, retention, deletion, subprocessors, escalation rules, and human review are easier to evaluate than vague AI promises.

  • Review failed calls, low-confidence answers, and human escalations.
  • Update approved knowledge instead of letting the agent guess.
  • Tune routing rules when the wrong team receives calls.
  • Reconfirm disclosure, retention, and fallback rules before expanding coverage.