EVREEVRE
SECURITY

Critical conversations.
Controlled data.

Identity, data, and AI flows are designed together, with a clear access boundary at every layer.

EVRE / CONVERSATION BOUNDARY
RAW SIGNAL
POLICY MEMBRANE
CONTROLLED FLOW
CAPTUREBOUNDARYRELEASE
FOUNDATIONAL CONTROLS

Data isolation

Row-level authorization checks separate customer data at the database layer.

Primary runtime and data region

The primary application runtime and data layer run in the Frankfurt region.

Privileged access

Multi-factor authentication protects administrative access to production services.

Custom voice-processing boundaries

For customer-specific voice profiles, participant audio may be processed in a private or local STT layer; data sent to external speech providers can be restricted.

DATA FLOW

How data moves.

The primary application runtime and data layer run in the Frankfurt region. AI, voice, and infrastructure providers are used only for data required for the relevant function.

01CLIENTBrowser · TLS · session
02APPLICATIONPrimary server runtime · Frankfurt
03DATAPrimary data layer · Frankfurt
04RESTRICTEDRestricted external services
DEPLOYMENT MODELS

One product. Different data boundaries.

EVRE can be configured across different data and infrastructure boundaries, from standard cloud to customer-controlled infrastructure.

01

Standard Cloud

Managed EVRE infrastructure

The primary application runtime and data layer run in the Frankfurt region.

AI, voice, and infrastructure providers are used only for data required for the relevant function.

02

Private / Regional

Enterprise use with additional data boundaries

Private speech processing, regional services, customer-specific provider routing, and additional data minimisation may be applied according to deployment requirements.

Provider and data boundaries are configured for the relevant customer and service scope.

03

Customer-Managed / On-Premises

Customer-controlled infrastructure

The application and selected AI, speech, and data components can be configured to run in customer-controlled cloud, private infrastructure, or on-premises environments.

Component scope is defined in the technical design and customer agreement.

Each deployment's data location, provider boundary, and customer-controlled components are defined by its technical and contractual scope.

CONTROLS IN OPERATION

Controls and scope.

Access, application, data, and provider layers are protected by independent controls.

01Logical tenant isolation

Workspace membership, role, ownership, and row-level authorization checks restrict access to customer records.

02Identity and access management

Authenticated sessions, role-based permissions, and server-side privileged credentials limit access to protected functions.

03Application and network security

Encrypted transport, origin validation, browser security policies, and server-side request controls reduce the exposed attack surface.

04AI and voice service controls

Data sent to external AI and voice services is limited by purpose, data type, deployment profile, and server-side routing policies.

05Encryption and secrets management

Encryption controls are used for data in transit and at rest across application and infrastructure layers. Application keys and provider credentials are kept outside the browser.

06Backup and recovery

Regular restore points support service recovery and business continuity procedures.

07Third-party service governance

Service providers are assessed according to their role, data access, processing location, security terms, and contractual obligations.

08Security reporting

Suspected vulnerabilities can be reported through the published security contact for coordinated review and remediation.

REVIEW AND EVIDENCE

Material for review.

Public disclosures, contractual documents, and technical security materials are separated according to their purpose.

01Public privacy and security disclosures
02Contractual terms for the agreed service scope
03Technical architecture and control evidence on request
Technical review

Review EVRE with your team.

Access public notices directly, or contact us to review the DPA, subprocessor information, data flows, and customer-specific technical scope.

For vulnerability disclosure, do not access personal data or disrupt production services.