Security at Gideon
How we protect the confidentiality, integrity, and availability of your data.
We recognise that the confidentiality, integrity, and availability of the information and data we create, maintain, and host are vital to the success of your business and the privacy of your clients and their callers.
As a service provider, we believe in providing clear information about our security practices, tools, resources, and responsibilities, so that our customers can feel confident in choosing us as a trusted provider. This page highlights the steps we take to identify and mitigate risks, implement best practices, and continuously develop ways to improve.
For live compliance status, detailed controls, policies, and reports, visit our Trust Center at trust.callgideon.com or request access at gideon@callgideon.com.
Compliance
HIPAA — Certified. We operate as a HIPAA Business Associate and execute BAAs with customers before ePHI is transmitted.
SOC 2 — Certified. Our security program is designed and operated in alignment with SOC 2, managed on a continuous-compliance platform.
ISO/IEC 27001 v2022 — Compliant. Our information-security management practices align with ISO/IEC 27001:2022.
GDPR — Certified posture. We operate U.S.-only today and maintain GDPR-aligned practices; see our Privacy Policy for jurisdictional detail.
AI Security Posture
Training on customer data: none — we do not train generalized models on your data.
Data retention: 12 months for application logs, with configurable retention for call recordings and transcripts.
Stability: 99.9% platform stability target with graceful degradation and human-in-the-loop fallback.
Cost model: tiered — no data-monetization; we never sell data.
Controls
Product security
Production system user review
Vulnerability remediation process
Centralized management of flaw remediation processes
Data security
Identity validation
Termination-of-employment access revocation
Multi-factor authentication
Network security
Impact analysis
Limited network connections; deny-by-default security groups
Review of external system connections
App security
Conspicuous link to privacy notice
Monitoring for unauthorized activities
Login session controls
Endpoint security
Malicious code protection (anti-malware)
Full device or container-based encryption
Endpoint security validation
Corporate security
Code of business conduct
Competency screening
Personnel screening
Dozens of additional controls, policies, and procedures — including our Communications & Network Security Policy, Asset Management Policy, Acceptable Usage Policy, Access Control Policy, and Compliance Policy — are published in the Trust Center.
Subprocessors
We rely on a small set of vetted subprocessors, including PostHog (analytics), Notion (product management), Deepgram and Anthropic (artificial intelligence), Supabase (IT infrastructure), and Tailscale (security software), among others. AI and voice providers that may process ePHI are engaged under zero-/no-data-retention terms and/or BAAs. The complete, current list is available in the Trust Center and in our Privacy Policy.
Your Data
Want to access or modify your data? Send a request to gideon@callgideon.com to request access, updates, migration, or deletion, and we’ll get it done for you. See our Privacy Policy for how requests are routed depending on whether Gideon acts as a controller or as your firm’s processor / Business Associate.
Security at Gideon
How we protect the confidentiality, integrity, and availability of your data.
We recognise that the confidentiality, integrity, and availability of the information and data we create, maintain, and host are vital to the success of your business and the privacy of your clients and their callers.
As a service provider, we believe in providing clear information about our security practices, tools, resources, and responsibilities, so that our customers can feel confident in choosing us as a trusted provider. This page highlights the steps we take to identify and mitigate risks, implement best practices, and continuously develop ways to improve.
For live compliance status, detailed controls, policies, and reports, visit our Trust Center at trust.callgideon.com or request access at gideon@callgideon.com.
Compliance
HIPAA — Certified. We operate as a HIPAA Business Associate and execute BAAs with customers before ePHI is transmitted.
SOC 2 — Certified. Our security program is designed and operated in alignment with SOC 2, managed on a continuous-compliance platform.
ISO/IEC 27001 v2022 — Compliant. Our information-security management practices align with ISO/IEC 27001:2022.
GDPR — Certified posture. We operate U.S.-only today and maintain GDPR-aligned practices; see our Privacy Policy for jurisdictional detail.
AI Security Posture
Training on customer data: none — we do not train generalized models on your data.
Data retention: 12 months for application logs, with configurable retention for call recordings and transcripts.
Stability: 99.9% platform stability target with graceful degradation and human-in-the-loop fallback.
Cost model: tiered — no data-monetization; we never sell data.
Controls
Product security
Production system user review
Vulnerability remediation process
Centralized management of flaw remediation processes
Data security
Identity validation
Termination-of-employment access revocation
Multi-factor authentication
Network security
Impact analysis
Limited network connections; deny-by-default security groups
Review of external system connections
App security
Conspicuous link to privacy notice
Monitoring for unauthorized activities
Login session controls
Endpoint security
Malicious code protection (anti-malware)
Full device or container-based encryption
Endpoint security validation
Corporate security
Code of business conduct
Competency screening
Personnel screening
Dozens of additional controls, policies, and procedures — including our Communications & Network Security Policy, Asset Management Policy, Acceptable Usage Policy, Access Control Policy, and Compliance Policy — are published in the Trust Center.
Subprocessors
We rely on a small set of vetted subprocessors, including PostHog (analytics), Notion (product management), Deepgram and Anthropic (artificial intelligence), Supabase (IT infrastructure), and Tailscale (security software), among others. AI and voice providers that may process ePHI are engaged under zero-/no-data-retention terms and/or BAAs. The complete, current list is available in the Trust Center and in our Privacy Policy.
Your Data
Want to access or modify your data? Send a request to gideon@callgideon.com to request access, updates, migration, or deletion, and we’ll get it done for you. See our Privacy Policy for how requests are routed depending on whether Gideon acts as a controller or as your firm’s processor / Business Associate.