Skip to main content
At Famulor, data sovereignty is a baseline requirement of modern AI communication. This Trust Center gives full transparency into our infrastructure, our specialized sub-processors, and the technical safeguards that protect sensitive data. This page serves as a living annex to our Data Processing Addendum (DPA) and is updated regularly to match our current technology stack. Terms like LLM, STT, TTS, SIP trunk, or realtime model are explained in the Glossary.

Infrastructure security

Every layer of our platform is built on security-first principles.

Encryption

AES-256 encryption at rest, TLS 1.3 in transit. Voice data, transcripts, and customer information are encrypted end-to-end across the full call lifecycle.

Access control

Role-based access control (RBAC) and least-privilege principles across all systems. Every access is logged and auditable.

Monitoring & detection

24/7 security monitoring with intrusion-detection systems, anomaly alerting, and comprehensive audit logging for all system activity.

Business continuity

Automated backups, disaster-recovery procedures, and a 99.9% availability SLA. Redundant infrastructure across multiple availability zones.

Incident response

A documented incident-response plan with defined escalation procedures, compliance with GDPR’s 72-hour breach-notification requirement, and post-incident review.

Sub-processor security

Every AI sub-processor is reviewed for security and compliance before it’s added to the platform. Native, EU-resident plugins are used wherever available for the highest-sensitivity workloads (see Speech services below).

1. Our sovereignty commitments

To meet the strict requirements of the European market — including GDPR Art. 9 for healthcare and other sensitive-data use cases — we operate on four principles:
An earlier version of this page described a “Zero Retention Mode” that processed data purely in memory. That specific mode is not part of the current platform — minimization today works through the configurable retention windows above, down to one month. If your organization needs a stricter guarantee, contact support@famulor.io.

2. System status & availability

Transparency about system performance matters to us. You can check live status at any time: Live status: https://status.famulor.io/

3. Infrastructure & platform hosting

These providers host the Famulor platform, including backend logic, databases, and the customer dashboard.

4. Artificial intelligence (LLM)

These models handle reasoning and conversation logic. Model access is routed through an AI gateway with enterprise-grade data handling; native, direct connections are used for select providers where EU data residency requires it. Note: LLM, STT, TTS, and SIP trunk providers are selectable per assistant, depending on the use case.

5. Speech services (STT & TTS)

Specialized providers for real-time transcription (speech-to-text) and speech synthesis (text-to-speech). Famulor’s engine-mode architecture (Pipeline / Realtime / Half-Cascade) determines which of these run for a given assistant. Note: LLM, STT, TTS, and SIP trunk providers are selectable per assistant, depending on the use case.
Not every provider listed above processes every call. Famulor selects EU-resident, native connections for higher-sensitivity workloads (Soniox, Gladia, Azure) and uses a managed inference path for the rest — both are covered by the transfer safeguards in section 10.

6. Business operations & billing

Providers for transactional security and administrative management.

7. WhatsApp Business processing

For WhatsApp Business:
  • The integration connects directly to Meta’s WhatsApp Cloud API — not routed through Twilio.
  • You can use either your own WhatsApp-enabled number or a number from the Famulor number pool (depending on setup/verification).
  • If using your own number, the number owner must complete verification directly in Meta Business Manager.
  • Inbound WhatsApp messages are processed through configurable LLM workflows.
  • Replies are sent back as an AI-generated message.
  • Text, images, and voice messages can be processed within the enabled assistant configuration and used for reply generation.

8. Platform analytics

For product analytics on the dashboard itself, Famulor uses:
Famulor’s documentation site (docs.famulor.io) separately uses Google Analytics 4 and Microsoft Clarity for content analytics — these do not process data from your workspace or calls. White-label customers may optionally connect their own Google Tag Manager, GA4, or Meta Pixel to their own branded domain; that configuration and its data are the customer’s own.
The legal entity behind each provider, with a publicly available business address (as of the date below). Newer providers added since our last full review are marked — contact support@famulor.io for their current entity details pending the next quarterly update.

10. International data transfers & safeguards

For providers with US parent companies (e.g. Microsoft, Google, Vercel, Groq, ElevenLabs, Deepgram, Cartesia, LiveKit), Famulor ensures compliance through:
  • Data residency: configuring services so data is processed exclusively on EU nodes wherever the provider offers it.
  • Legal framework: use of the EU-U.S. Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs).
  • Enterprise agreements: contracts that exclude third-party access and model-training use of your data.
  • TIA on request: for enterprise customers, Famulor prepares a Transfer Impact Assessment (TIA) on request, per EDPB Recommendations 01/2020, for any provider with a US parent company.
For providers without DPF certification, Famulor has executed the EU Standard Contractual Clauses under EU Commission Decision 2021/914/EU (Module 2: Controller to Processor). These are available to enterprise customers on request. To independently verify a provider’s DPF certification: Data Privacy Framework Participants List

11. Data retention

Retention periods are available in your account and configurable per data category.

12. Technical and organizational measures (TOMs)

Our security framework targets maximum traceability and isolation:

13. Governance & maintenance

  • This list is reviewed quarterly.
  • Changes to the provider stack are documented in the Changelog.
Last updated: 2026-08-27

14. Google API disclosure

Where Famulor’s Google Calendar and other Google Workspace integrations use information from Google APIs, that use and any onward disclosure to other applications complies with the Google API Services User Data Policy, including its Limited Use requirements.