Security at Gideon

How we protect the confidentiality, integrity, and availability of your data.

We recognise that the confidentiality, integrity, and availability of the information and data we create, maintain, and host are vital to the success of your business and the privacy of your clients and their callers.

As a service provider, we believe in providing clear information about our security practices, tools, resources, and responsibilities, so that our customers can feel confident in choosing us as a trusted provider. This page highlights the steps we take to identify and mitigate risks, implement best practices, and continuously develop ways to improve.

For live compliance status, detailed controls, policies, and reports, visit our Trust Center at trust.callgideon.com or request access at gideon@callgideon.com.

Compliance

  • HIPAA — Certified. We operate as a HIPAA Business Associate and execute BAAs with customers before ePHI is transmitted.

  • SOC 2 — Certified. Our security program is designed and operated in alignment with SOC 2, managed on a continuous-compliance platform.

  • ISO/IEC 27001 v2022 — Compliant. Our information-security management practices align with ISO/IEC 27001:2022.

  • GDPR — Certified posture. We operate U.S.-only today and maintain GDPR-aligned practices; see our Privacy Policy for jurisdictional detail.

AI Security Posture

  • Training on customer data: none — we do not train generalized models on your data.

  • Data retention: 12 months for application logs, with configurable retention for call recordings and transcripts.

  • Stability: 99.9% platform stability target with graceful degradation and human-in-the-loop fallback.

  • Cost model: tiered — no data-monetization; we never sell data.

Controls

Product security

  • Production system user review

  • Vulnerability remediation process

  • Centralized management of flaw remediation processes

Data security

  • Identity validation

  • Termination-of-employment access revocation

  • Multi-factor authentication

Network security

  • Impact analysis

  • Limited network connections; deny-by-default security groups

  • Review of external system connections

App security

  • Conspicuous link to privacy notice

  • Monitoring for unauthorized activities

  • Login session controls

Endpoint security

  • Malicious code protection (anti-malware)

  • Full device or container-based encryption

  • Endpoint security validation

Corporate security

  • Code of business conduct

  • Competency screening

  • Personnel screening

Dozens of additional controls, policies, and procedures — including our Communications & Network Security Policy, Asset Management Policy, Acceptable Usage Policy, Access Control Policy, and Compliance Policy — are published in the Trust Center.

Subprocessors

We rely on a small set of vetted subprocessors, including PostHog (analytics), Notion (product management), Deepgram and Anthropic (artificial intelligence), Supabase (IT infrastructure), and Tailscale (security software), among others. AI and voice providers that may process ePHI are engaged under zero-/no-data-retention terms and/or BAAs. The complete, current list is available in the Trust Center and in our Privacy Policy.

Your Data

Want to access or modify your data? Send a request to gideon@callgideon.com to request access, updates, migration, or deletion, and we’ll get it done for you. See our Privacy Policy for how requests are routed depending on whether Gideon acts as a controller or as your firm’s processor / Business Associate.

Security at Gideon

How we protect the confidentiality, integrity, and availability of your data.

We recognise that the confidentiality, integrity, and availability of the information and data we create, maintain, and host are vital to the success of your business and the privacy of your clients and their callers.

As a service provider, we believe in providing clear information about our security practices, tools, resources, and responsibilities, so that our customers can feel confident in choosing us as a trusted provider. This page highlights the steps we take to identify and mitigate risks, implement best practices, and continuously develop ways to improve.

For live compliance status, detailed controls, policies, and reports, visit our Trust Center at trust.callgideon.com or request access at gideon@callgideon.com.

Compliance

  • HIPAA — Certified. We operate as a HIPAA Business Associate and execute BAAs with customers before ePHI is transmitted.

  • SOC 2 — Certified. Our security program is designed and operated in alignment with SOC 2, managed on a continuous-compliance platform.

  • ISO/IEC 27001 v2022 — Compliant. Our information-security management practices align with ISO/IEC 27001:2022.

  • GDPR — Certified posture. We operate U.S.-only today and maintain GDPR-aligned practices; see our Privacy Policy for jurisdictional detail.

AI Security Posture

  • Training on customer data: none — we do not train generalized models on your data.

  • Data retention: 12 months for application logs, with configurable retention for call recordings and transcripts.

  • Stability: 99.9% platform stability target with graceful degradation and human-in-the-loop fallback.

  • Cost model: tiered — no data-monetization; we never sell data.

Controls

Product security

  • Production system user review

  • Vulnerability remediation process

  • Centralized management of flaw remediation processes

Data security

  • Identity validation

  • Termination-of-employment access revocation

  • Multi-factor authentication

Network security

  • Impact analysis

  • Limited network connections; deny-by-default security groups

  • Review of external system connections

App security

  • Conspicuous link to privacy notice

  • Monitoring for unauthorized activities

  • Login session controls

Endpoint security

  • Malicious code protection (anti-malware)

  • Full device or container-based encryption

  • Endpoint security validation

Corporate security

  • Code of business conduct

  • Competency screening

  • Personnel screening

Dozens of additional controls, policies, and procedures — including our Communications & Network Security Policy, Asset Management Policy, Acceptable Usage Policy, Access Control Policy, and Compliance Policy — are published in the Trust Center.

Subprocessors

We rely on a small set of vetted subprocessors, including PostHog (analytics), Notion (product management), Deepgram and Anthropic (artificial intelligence), Supabase (IT infrastructure), and Tailscale (security software), among others. AI and voice providers that may process ePHI are engaged under zero-/no-data-retention terms and/or BAAs. The complete, current list is available in the Trust Center and in our Privacy Policy.

Your Data

Want to access or modify your data? Send a request to gideon@callgideon.com to request access, updates, migration, or deletion, and we’ll get it done for you. See our Privacy Policy for how requests are routed depending on whether Gideon acts as a controller or as your firm’s processor / Business Associate.