Trust · Security
Enterprise-grade security, from the first line of code.
TextGopher™ handles calls, texts, and the details customers share — on behalf of the businesses that trust us. Protecting that data isn’t a feature we added later. It’s verified on every request, isolated per account, and built into the product from the start.
Have a security or procurement team? We’re glad to walk them through our controls.
Core controls
The controls a security review looks for.
Each of these is implemented today, and re-checked when we ship anything new.
Verified at the door
Every inbound Twilio and Stripe webhook has its signature validated before we act on it. An unverified request is rejected — no exceptions, on every route.
Isolated by tenant
Every account’s data is separated at the query layer, so one business can never see another’s — and the AI only ever sees the account it’s working for.
Encrypted credentials
Provider auth tokens are encrypted at rest with AES‑256‑GCM. Passwords use argon2id, and session and reset tokens are stored only as SHA‑256 hashes.
Safe data access
All database access uses parameterized statements, and any dynamic field is allowlisted — so customer data can’t be reached through injected input.
Secrets stay in the vault
Every key and token is sourced from a secrets vault at deploy time. Nothing sensitive lives in our source code — or anywhere in its history.
Append-only audit trail
Significant actions are written to an audit log that can’t be edited or deleted — alongside a durable ledger of every AI commitment decision.
Caller data
We protect what callers share.
A missed call carries real personal detail. We hold it carefully and keep only what a business needs to respond.
- Traffic is encrypted in transit with TLS.
- We capture only what’s needed to respond to a caller — the problem, timing, and how to reach them.
- Message content and personal phone numbers stay out of our application logs.
- Access to production data is limited and least‑privilege.
- Data is retained per our retention policy and removed when it’s no longer needed.
- We never sell caller data, and we don’t share it for anyone else’s marketing.
For how requests to access or delete data are handled, see Your Privacy Rights.
AI, handled responsibly
The AI gathers. A person decides.
TextGopher™ uses AI to understand a caller and organize the request — never to commit your business.
Human in the loop
Every outcome is reviewed and decided by a person at your business. The AI recommends the next action; it doesn’t take it.
The Commitment Firewall
TextGopher™ never quotes a price, promises service, or confirms an appointment — and every AI commitment decision is recorded.
Fair Housing safeguards
For real estate, a Fair Housing filter screens responses. It stays on for that vertical — it can’t be switched off.
More on how we use AI: Responsible AI.
Governance
Everything your review needs.
The policies and agreements a security or procurement team asks for, in one place.
Responsible disclosure
Found a security issue? Tell us.
We investigate every report, act on valid issues quickly, and won’t pursue legal action against good‑faith research that respects our users’ privacy and data.
- Give us reasonable time to investigate and fix before any public disclosure.
- Don’t access, modify, or delete data that isn’t yours — and never spam or degrade the service.
- Don’t violate the privacy of callers or businesses using TextGopher™.
Missed-call recovery you can sign off on.
Bring TextGopher™ to your business with the controls in place from day one.