Rosli

Security & data

Plain words about what we keep, where it lives, and who can see it.

Insurance offices handle nonpublic personal information all day. Here is exactly what is in place today, what we are building next, and the vendors that touch a call. No marketing language.

In place today

What every call goes through

Callers hear the disclosure first

Every call opens with "automated assistant, this call may be recorded" so all-party-consent states are covered.

No call recordings

We keep a text transcript so the summary can be written; we store no audio and neither does our telephony provider. Our speech provider (OpenAI) may retain audio for up to 30 days for abuse monitoring under its standard API terms.

Logs carry no caller details

Names, numbers, addresses and policy details are redacted before anything reaches a log line. A test in our build fails if that guard is removed.

Returning-caller memory keeps safe fields only

Name, language, email, address, date of birth, call count. Never a license number, VIN or violation history.

Every screen is behind sign-in

Your dashboard uses a magic link sent only to the addresses you list. Our own operations pages are password-protected.

Encrypted in transit and at rest

TLS everywhere, including the phone leg (SRTP); the database encrypts storage (AES-256). Webhooks are signature-verified so nobody can forge a call or event.

The AI never quotes, binds or advises

The E&O boundary is a product rule: those callers reach a licensed person on the first turn.

Building next

Three things we are finishing before we ask for a card

  • 1Field-level encryption for license numbers, VINs and dates of birth, and dropping those fields once the summary is delivered.
  • 2A 30-day purge of sensitive intake fields by default, with a retention period you can set per office.
  • 3A signed security addendum: encryption, 72-hour breach notice, deletion, and the subprocessor list below.

Your rights

Your data, your callers' data

Delete on request. Email support@rosli.ai with the office and the phone number; the caller's memory and call records are removed and we confirm in writing. Closing your account deletes the office's data the same way.

Export. Every call and its transcript is visible in your dashboard; ask us for a CSV export at any time.

Your mailbox is yours. Summary emails contain caller details in plain text because that is how your office works today. Secure the mailbox the way you secure customer email, and tell us if you would rather receive a link to the dashboard instead of the details.

Questionnaires. Send your carrier's or your compliance team's vendor questionnaire to support@rosli.ai; we answer them in full.

Subprocessors

Who touches a call

These are the only vendors in the path of a call or an email. All are contracted under their standard business terms; none receives data beyond what its role needs.

VendorRoleRegion
TwilioTelephony (your Rosli number, transfers)United States
OpenAISpeech and language model for the conversationUnited States
Supabase (Postgres)Call records, transcripts, office settingsUnited States (Oregon)
RenderApplication hostingUnited States (Oregon)
ResendSummary and sign-up emailsUnited States

Also a security control

What Rosli never does on a call

  • Quote a price, rate or premium
  • Answer "am I covered for…?"
  • Bind, activate or confirm coverage
  • Advise on a claim, or handle an injury, death or total-loss claim alone
  • Take card numbers or health details
  • Keep an angry, distressed or legal-threat caller away from a human

Questions for your compliance team?

Email support@rosli.ai. We answer vendor questionnaires in full.

$0 setup · month to month · keep your number · no card at sign-up