CallVault Trust

Last updated 2026-05-29

CallVault is built on trusted infrastructure and a default-secure architecture.

We're 7x Systems LLC, a Wyoming-registered limited liability company operating CallVault — the long-term call intelligence vault for revenue teams who need their conversation history to stay queryable, secure, and theirs. Headquartered at 1309 Coffeen Ave, Ste 17642, Sheridan, WY 82801. Contact: support@callvaultai.com or +1 315-335-8779.

This page documents how we handle customer data, who processes it on our behalf, and how to reach us with security questions.

At a glance

Encryption in transit
TLS 1.2+ on every endpoint
Encryption at rest
AES-256 (Supabase managed)
Data isolation
RLS per organization and workspace
Authentication
MFA enforced on all admin accounts
Audit logging
Every MCP tool call logged
Deletion
Self-serve at every level
Security contact
support@callvaultai.com (5 business day SLA)

Certifications and inheritance

CallVault is a Wyoming LLC operated by a single principal as of May 2026. We are not currently SOC 2 attested. We are in active preparation for SOC 2 Type I and expect to engage an external auditor in 2026.

While we work toward attestation, the infrastructure CallVault runs on is independently audited. Our customers inherit material coverage from these providers:

ProviderRole at CallVaultIndependent attestations
SupabaseDatabase, authentication, Edge FunctionsSOC 2 Type II, HIPAA-eligible plans, GDPR DPA available
VercelFrontend hosting, edge functions, CI/CDSOC 2 Type II, ISO 27001:2022, HIPAA BAA on Enterprise plan, EU-US Data Privacy Framework certified
Stripe (via Polar)Payment processingPCI DSS Level 1, SOC 1 & 2 Type 2, ISO 27001, EU-US DPF
AnthropicAI inference (via OpenRouter, on customer invocation only)SOC 2 Type II, HIPAA BAA available, ISO 27001
OpenAIAI inference (via OpenRouter, on customer invocation only)SOC 2 Type II, CSA STAR Level 1, HIPAA BAA available

Inheritance is not the same as attestation, and we don't claim otherwise. The cells above link to each provider's public trust documentation so you can verify directly.

Subprocessors

A subprocessor is a third party that processes customer data on CallVault's behalf. The current list:

SubprocessorPurposeCustomer data processed
SupabaseDatabase, authentication, Edge FunctionsTranscripts, contacts, account records, MCP tokens, OAuth grants
VercelFrontend hosting, edge functions, CI/CDRequest logs, deployment metadata (does not include transcript content)
PolarSubscription billingBilling email, subscription state
StripePayment processing (under Polar)Card data (Stripe-hosted Checkout iframe; never touches CallVault servers)
OpenRouterLLM routing layer for AI-tier MCP toolsTranscript text submitted at AI-tool invocation only
AnthropicLLM provider (via OpenRouter)Transcript text submitted at AI-tool invocation only
OpenAILLM provider (via OpenRouter)Transcript text submitted at AI-tool invocation only

We commit to notifying customers at least 15 days before adding a new subprocessor that will process their data.

Data handling

Where your data lives

Your CallVault data resides primarily in our Supabase project. Access is controlled at the database layer by Row Level Security policies that scope data to your organization and (optionally) workspace.

What we collect

The minimum required to deliver the service: the transcript text and metadata you ingest; your account profile (name, email, authentication identifier); your organization and workspace structure; records of MCP tokens and OAuth grants you issue; operational logs (which tools were called, when, by which organization).

What we don't do

Retention

We retain your data for the lifetime of your account by default. CallVault is a long-term call intelligence vault, and customers expect data ingested today to remain queryable years from now. You can delete your data at any time:

Backups

Supabase manages encrypted backups of our production database with retention per their plan tier. We have successfully tested restore from these backups. Deleted data may persist in backup snapshots until the retention window expires.

Export

You can export your data via the MCP API at any time using the read-tier tools (list_calls, get_transcript, list_contacts, list_folders, and others). The full schema is documented in our developer documentation.

Security controls

Logical access. Production access is restricted to the single principal of 7x Systems LLC. MFA is enforced on every production admin account. The credential vault is 1Password. All workforce credentials and access reviews are governed by our Access Control Policy.

Network. All public CallVault endpoints serve over TLS 1.2+. Inter-service communication between the frontend, Edge Functions, and Supabase uses authenticated and encrypted channels.

Application. All production code changes require peer review and are merged to main through GitHub branch protection rules. Every MCP tool call passes through a category-gating layer that enforces customer-issued scope before reaching any database query. The boundary is unit-tested in CI.

Cryptography. Data at rest is encrypted by Supabase using AES-256. TLS certificates are managed by Vercel and rotate automatically. Secret material (API keys, service role keys) is stored exclusively in 1Password or platform-managed secret stores and is never committed to source control.

Monitoring. Sentry monitors the frontend and Edge Functions. Supabase, Vercel, and GitHub provide platform-level audit logs. We perform quarterly access reviews and annual subprocessor reviews.

Change management. Production deploys are auto-triggered by merges to main on Vercel. Rollback is instant via the Vercel deployment history. All changes are reviewable in git.

Incident response. We maintain an Incident Response Plan that defines detection, classification, containment, eradication, communication, and post-mortem procedures. We have not had a security-relevant incident in the trailing twelve months. When we do, we will report transparently per the Plan.

Compliance posture

ProgramStatus
SOC 2 Type IIn preparation; external audit planned for 2026
SOC 2 Type IITargeted after Type I completion
GDPRDPA available; subprocessor list public; data deletion supported
CCPA / CPRAHonored on customer request via support@callvaultai.com
HIPAANot a HIPAA-eligible service at this time. Customers with PHI use cases should contact us before ingesting Protected Health Information.
PCI DSSOut of scope — payment data is handled by Stripe-hosted Checkout via Polar; no card data ever reaches CallVault servers
ISO 27001Not currently pursued

Send us your security questionnaire

We respond to mid-market and enterprise security questionnaires within 5 business days. Send your CAIQ, SIG, custom vendor security questionnaire, or DPA to support@callvaultai.com with [Security Review] in the subject line. Our pre-filled CAIQ-Lite response is available on request for SMB and mid-market evaluations.

Report a vulnerability

If you believe you've found a security vulnerability in CallVault, please email support@callvaultai.com with [Security Vulnerability] in the subject line. We commit to acknowledge your report within 2 business days, provide an initial triage response within 5 business days, and coordinate disclosure timing with you in good faith. We do not currently operate a paid bug bounty program. We will credit researchers who report responsibly disclosed vulnerabilities, with the researcher's permission.

Status

CallVault is operational. A public status page is being provisioned and will be linked here.

Documents

Public

DocumentURL
Terms of Servicecallvaultai.com/terms
Privacy Policycallvaultai.com/privacy
Cookie Policycallvaultai.com/cookies
Data Processing Addendum (DPA)callvaultai.com/dpa

On request

DocumentAvailability
Information Security PolicyOn request, under NDA
Access Control PolicyOn request, under NDA
Data Classification PolicyOn request, under NDA
Data Retention & Deletion PolicyOn request, under NDA
Incident Response PlanOn request, under NDA
Vendor & Subprocessor Management PolicyOn request, under NDA
Pre-filled CAIQ-Lite responseOn request

This page was last updated on 2026-05-29. We refresh it at least quarterly and on any material change to the subprocessor list, security controls, or compliance posture.

Questions: support@callvaultai.com