← Back to MicHelper
🛡️ Enterprise-Grade Security

Your Data, Protected

MicHelper is built with security and privacy at its core. We implement industry-leading practices to ensure your sales data remains confidential and compliant.

🔐

Encryption Everywhere

Sensitive data (transcripts, personal information) is encrypted at rest using AES-256-GCM. Audio recordings are processed transiently and deleted immediately after transcription. All data in transit uses TLS 1.2 or higher.

👥

Role-Based Access Control

Granular RBAC ensures users only see data relevant to their role. Sellers see their own data, managers see their teams, admins manage the network.

📋

Comprehensive Audit Logs

Every action is logged with timestamps, user IDs, and IP addresses. Full audit trail for compliance and security investigations.

🎙️

Transcript-Only Mode

Configure MicHelper to automatically delete audio after transcription, keeping only the text. Minimize data footprint while maintaining quality insights.

⏱️

Configurable Retention

Set custom retention periods for audio, transcripts, and metadata. Automatic deletion ensures you only keep data as long as needed.

Consent Management

Built-in tools to manage customer and employee consent for recordings. Document compliance with local privacy regulations.

Technical Security Measures

We implement multiple layers of protection to safeguard your data.

Secure Authentication

Secure session management with automatic timeouts and IP-based session validation. Two-factor authentication is planned for a future release.

API Security

Token-based authentication, rate limiting, request signing for webhooks, and comprehensive input validation.

Network Security

HTTPS-only connections, HSTS enforcement, security headers (CSP, X-Frame-Options, Referrer-Policy).

Infrastructure Security

Hosted on Render.com cloud platform, which maintains SOC 2 Type II certification. MicHelper inherits infrastructure-level security controls from the hosting provider.

Data Isolation

Each customer network is logically isolated. Cross-tenant access is architecturally prevented.

Authentication & Access Control

Data Protection

Infrastructure Security

Audit & Monitoring

Data Lifecycle

Data TypeRetentionEncryption
Raw audioDeleted immediately after transcriptionTLS in transit, not encrypted at rest (transient)
Transcripts7 days default (configurable)AES-256-GCM field-level
Analytics & scoresUp to 500 daysDatabase-level
Account dataSubscription + 30 daysAES-256-GCM for sensitive fields
Audit logs90 daysDatabase-level

Privacy & Compliance

MicHelper helps you meet regulatory requirements while gaining valuable sales insights.

GDPR Ready

Built with GDPR principles: data minimization, purpose limitation, right to erasure, and data portability.

Data Processing Agreement

Standard DPA available for all customers. We act as a processor on your behalf.

Privacy Requests

In-app tools for data export and deletion requests. Respond to data subject requests efficiently.

Breach Notification

Documented incident response procedures. Notification within 72 hours as required by GDPR.

Data Lifecycle & Retention

Audio Recordings

Raw audio recordings are processed transiently. Audio is uploaded to our servers solely for the purpose of transcription. Once transcription is complete, the original audio file is permanently deleted immediately. Audio is never stored long-term on our servers. During the brief processing window, audio is encrypted in transit (TLS 1.2+) and at rest (AES-256-GCM).

Transcripts

Text transcripts generated from audio recordings are stored for a default period of 7 days, after which they are automatically and permanently deleted. This retention period is configurable by the customer (network administrator). Transcripts are encrypted at rest using AES-256-GCM field-level encryption.

Analytics, Scores & Performance Data

Aggregated analytics data, compliance scores, performance ratings, KPI metrics, and point balances are retained for up to 500 days and are continuously updated as new interactions are processed. This data represents computed metrics and does not contain raw audio or verbatim conversation text. Customers may request deletion through the account deletion process.

Account & Configuration Data

User accounts, network configurations, scripts, and system settings are retained for the duration of the active subscription and for 30 days following account termination to allow for data export.

Summary

Data Type Retention Encryption
Raw audio recordingsDeleted immediately after transcriptionAES-256-GCM (during processing)
Transcripts7 days (configurable)AES-256-GCM field-level
Analytics & scoresUp to 500 days (continuously updated)Database-level encryption
Account dataDuration of subscription + 30 daysAES-256-GCM for sensitive fields
🇪🇺
GDPR EU Data Protection
🔒
TLS 1.2+ Transport Security
🗄️
AES-256 At-Rest Encryption
📊
SOC 2 Cloud Infrastructure

Security Commitment & Limitations

MicHelper implements industry-standard security measures to protect your data, including but not limited to:

No Absolute Guarantee. While we employ robust, multi-layered security controls and follow industry best practices, no system connected to the internet can guarantee 100% security. We commit to:

If you discover a potential security vulnerability, please report it responsibly to security@michelper.app. We appreciate the security research community and will acknowledge valid reports.

Vulnerability Disclosure

We value the security research community and welcome responsible disclosure of security vulnerabilities.

Please do not access or modify other users' data, disrupt services, or publicly disclose vulnerabilities before we have had a reasonable opportunity to address them.

Questions About Security?

Our team is happy to discuss your specific security and compliance requirements.