Security

Last updated24 July 2026

This page states the security controls Artifically operates today. Every control listed is one we have built and run; there is nothing here that is planned, partial, or aspirational.

1Certifications

We hold no security certification, and we make no certification claims on this page or anywhere else on this site.

If your procurement process requires a certified processor today, Artifically does not meet that bar. We would rather tell you now than have you discover it later.

2Connected-tool credentials

When you connect a tool, we store the OAuth access token and, where the provider issues one, the refresh token. These are the most sensitive things we hold on your behalf.

  • Encrypted at rest with AES-256-GCM.
  • Encryption keys are managed through our application configuration and support rotation.
  • Never stored in plaintext.
  • Connector features that depend on the encryption key fail closed if it is unavailable — they stop rather than fall back to something weaker.
  • We request the narrowest scopes an automation needs, and disconnecting a tool deletes the credentials stored for that connection.

3Protecting your data

  • Data in transit is protected with TLS.
  • Call transcripts are redacted, then encrypted with a key specific to your organisation before being written to our database.
  • Caller phone numbers are stored only as a salted hash, never in the clear.
  • Payment-card numbers spoken during a call are detected, redacted from the transcript, and excluded from the recording.
  • Content passes through automated redaction before it is sent to a model provider, removing recognisable personal and secret data.
  • Data belonging to different customers is isolated at the automation-runtime level.

4Access and authentication

  • API keys are stored only as hashes. The full key is shown once, at creation, and cannot be retrieved afterwards.
  • Access to production systems is restricted.
  • Account access supports multi-factor authentication through our authentication provider.
  • Significant account and system activity is logged.

5Retention and deletion

Our retention periods are published in the Privacy Policy: 90 days for call transcripts, 13 months for call records and metrics, and 90 days after account deletion before permanent removal.

A caller to an Artifically-operated phone line can ask during the call for their data to be deleted. That request is carried out at the end of the call and is itself logged so it can be audited.

6Reporting a vulnerability

If you believe you have found a security vulnerability in Artifically, email legal@artifically.com with enough detail for us to reproduce it. We will acknowledge your report and keep you informed while we investigate.

Please give us a reasonable opportunity to fix the issue before disclosing it publicly. While investigating, do not access, modify, or delete data belonging to anyone else, and do not run tests that degrade the service for other customers — sections 6.2 and 6.3 of our Terms still apply.

We do not currently run a paid bug-bounty programme.

7If something goes wrong

If we discover a breach affecting your personal data, we will investigate it, contain it, and notify you and, where required, the relevant authority within the timeframes applicable law sets.

We do not offer contractual response-time commitments or service credits. How we handle service disruption is set out in section 10 of our Terms.

8Contact

Security reports and questions: legal@artifically.com.

Privacy questions and rights requests: privacy@artifically.com.