Every request between callers, your browser, and our services is encrypted with modern TLS. No plaintext hops.
Security you can verify, not just trust.
Enterprise buyers don’t want adjectives — they want controls they can check. Here is exactly how Switchboard encrypts your data, isolates your tenant, restricts access, and keeps an immutable record of everything the AI does. Stated plainly, with no certifications we haven’t earned.
Encrypted end to end — at rest, in transit, and in our logs.
Encryption is table stakes, so we make it boring and explicit rather than vague.
Stored data is encrypted at rest by default. Government tenants additionally get per-tenant AES-256-GCM keys for audit data.
Secrets and credentials are scrubbed from logs automatically, so tokens never linger in observability tooling.
How we handle your data
- US data residency — production data is stored in US regions.
- Webhook payloads are signature-verified, with replay protection on inbound events.
- Rate limiting and CSRF protection are enforced across endpoints.
- Sensitive customer data is minimized in logs by design, not by manual review.
Least privilege, enforced in code — and one tenant can never reach another.
Access is scoped at the role, the action, and the tenant boundary. Defense in depth, not a single gate.
Role-based access control
Tools and sensitive actions are gated by role. The receptionist can only invoke what its role permits — least privilege is enforced in code, not policy alone.
Step-up authentication
High-impact actions require a fresh, stronger proof of identity at the moment they run — not just a session that was valid an hour ago.
Passkeys / WebAuthn
Phishing-resistant passkey sign-in is supported for operators, removing shared-secret passwords from the most sensitive accounts.
Tenant isolation
Each tenant’s data is partitioned and scoped to that tenant. Government tenants can layer per-tenant encryption keys on top of logical isolation.
An append-only record is a security control — so we built one.
If an action can’t be quietly erased, accountability stops being a promise and becomes a property of the system.
Append-only by construction
Audit entries are written once. There is no edit path and no delete path — the record of what the AI did is structurally immutable.
Tamper-evident chaining
Government-tier logs are cryptographically chained, so any attempt to alter or remove a past entry breaks the chain and is detectable.
Every action logged
Each call and each tool invocation produces a durable record. “Every call answered, every action logged” is an architecture, not a slogan.
Government tenants can independently verify the chain and export FOIA-ready records — see the government overview for the public-sector specifics.
What’s certified, what’s in progress, and what’s on the roadmap.
We separate “how we’re built” from “what an auditor has signed.” You should never have to guess which is which.
Designed following SOC 2 principles
Our access controls, audit logging, and change practices are aligned to the SOC 2 trust principles today. This describes how the system is built — it is not a completed audit.
SOC 2 examination — in progress
We are actively pursuing a SOC 2 report. Until an independent auditor issues it, we will not describe ourselves as certified. Our Trust Center maps controls to evidence in the meantime.
FedRAMP-authorized infrastructure
Switchboard runs on Google Cloud regions that are FedRAMP-authorized. To be precise: the underlying infrastructure carries that authorization — the Switchboard application itself does not yet hold its own authorization.
GovRAMP / FedRAMP path for government
A GovRAMP-first authorization path (with FedRAMP reciprocity) is on our roadmap, alongside government deployment into Google Cloud Assured Workloads and Azure Government inference. Application authorization is a third-party assessment — never inherited from the cloud — so we will not claim it until it is achieved.
Found something? We want to hear from you.
Security is a collaboration. If you believe you’ve found a vulnerability, report it directly and we’ll work it in good faith.
Coordinated disclosure
Email a clear report — steps to reproduce, impact, and any proof of concept. Please give us a reasonable window to remediate before public disclosure, and avoid privacy violations, data destruction, or service degradation while testing.
- Report to security@switchboard.example
- We acknowledge reports and keep you updated on remediation.
- Good-faith research under this policy will not be pursued legally.
Get the full document package.
The Trust Center holds our threat model, control-by-control evidence, procurement answers, service levels, and disaster-recovery plan — everything your security review needs in one place.
Open the Trust Center