Security & Privacy

Your data is yours. Full stop.

Operator is built to run sensitive business workflows without treating your customer data, calls, or financial context like a growth asset.

Encryption
At rest & in transit
Financial access
Read-only context
Data usage
Never sold or shared for model training

What we commit to, in plain English

These are the product boundaries we try to make clear before you ever connect a phone number, bank feed, or customer workflow.

We never sell your data

Customer lists, business records, call transcripts, and financial context are not sold, licensed, or shared with advertisers.

We never train on your data

Your business data stays isolated to your account and is not used to train shared models.

You can export your data

You can request a full export at any time. If you leave, your data goes with you.

Financial access stays read-only

Bank connections are read-only. Operator can categorize activity, but it cannot move money without explicit approval.

Deletion requests are honored

If you need everything removed, we process account deletion and clean up retained operational data on a defined schedule.

Encryption is standard

Data is encrypted at rest and in transit using the same baseline protections expected from modern financial infrastructure.

Encrypted at restEncrypted in transitRead-only bank contextExport on requestDeletion workflowsClear vendor boundaries

Exactly what Operator can and can’t see

No surprises. Here’s the full data access map for the main product surfaces.

Call recordings

Operator can see
Limited

Transcripts only (you can disable).

Operator can do
Allowed

Extract information and train your knowledge base.

Bank transactions

Operator can see
Read-only

Read-only via Plaid.

Operator can do
Blocked

Cannot move money.

Customer data

Operator can see
Visible

Name, phone, and history.

Operator can do
Allowed

Book, follow up, and invoice.

Payroll details

Operator can see
Visible

Hours and rates you input.

Operator can do
Allowed

Calculate and submit via Gusto.

Passwords & logins

Operator can see
Never stored

Never stored.

Operator can do
Not applicable

Not applicable.

SSN / tax ID

Operator can see
Never requested

Never requested.

Operator can do
Not applicable

Not applicable.

Built on infrastructure you can trust

Operator leans on established infrastructure providers instead of inventing a custom security stack from scratch.

AWS

Core infrastructure runs on AWS-hosted systems with standard auditability, encryption, and access controls.

Plaid

Financial connections use read-only bank access so transaction context can be analyzed without exposing credentials to Operator.

Stripe

Payments and billing are processed through Stripe. Card data does not live in Operator systems.

Twilio

Voice and messaging flow through Twilio-backed infrastructure for call handling, routing, and notifications.

Questions? We’ll answer them directly.

If you need specifics about retention, integrations, exports, or how a particular workflow is handled, we’ll talk through it plainly.