Security & compliance

Built for calls with five- and six-figure consequences.

EZELIO launches into fintech, cybersecurity, recruitment, insurance and financial services — sectors where sales conversations are sensitive by nature. Our data protection posture is UK GDPR-first from day one, not bolted on later.

Verified-then-deleted recordings

The full recording is retained for a configurable window — 30 days by default — so you can review the call, then deleted automatically. Deletion is a verified pipeline stage: it only runs once the clips and call notes are confirmed present, and anything in doubt keeps the recording and raises an error rather than losing data.

UK/EU data residency

Recordings, clips and transcripts are stored in UK/EU-hosted object storage — eu-west-2 by default — encrypted in transit and at rest.

Org-scoped access

Tenant isolation is enforced in the database itself: every table holding call content carries a row-level security policy scoping it to the organisation that owns it, rather than relying on application code to remember.

Configurable retention

The retention window is a configured value, and a retention sweeper deletes recordings once it passes — deletion is a first-class operation with its own stage and its own audit trail, not a cron afterthought.

Per-call consent state

Every call carries an explicit consent state, moved only by a recorded event — the moment the bot is in the meeting and recording, or a decision logged by the rep. Declining is terminal and schedules the recording for deletion.

No silent capture

Capture is performed by a bot that joins as a visible, named participant in the meeting — there is no hidden or client-side recording path, and every supported platform raises its own recording indicator when it starts.

Compliance roadmap

Where we are, and what’s next.

We’d rather show you an honest roadmap than an inflated badge wall. Certifications below that aren’t marked “in place” have not been achieved yet.

Built in from day one

UK GDPR-aligned posture

The consent state machine, configurable retention and verified deletion are architectural requirements for Stage 1 of the build, not something added after the fact — they exist in the data model and the pipeline, not just in a policy.

Not yet written

Privacy notice, terms and DPA

A Data Processing Agreement template, a subprocessor register, a privacy notice and terms of service are required before we take a pilot organisation's data, and none of them are drafted yet. We would rather say so here than link you to a page that does not exist.

Planned — next

Cyber Essentials Plus

Certification planned alongside operational hardening: monitoring and error budgets, daily backups with tested restores, a staging environment and a public status page.

Future — enterprise stage

SOC 2 Type I, then Type II

Scoped for the point our roadmap reaches enterprise deals that require it, alongside SSO (SAML/OIDC) and SCIM provisioning.

Honesty note: EZELIO is pre-launch. The items above describe our security programme as scoped in our product requirements. Where a certification or control is not yet complete, we’ve labelled it as planned rather than claiming it’s done.