Trust & governance
Designed to the regulation, not retrofitted to it.
Voice AI fails in regulated sectors when compliance is bolted on after the demo. TRAI, RBI, IRDAI and DPDP were architectural constraints here from the first design review.
Regulatory alignment
Four regulators, four sets of controls, all enforced in code.
TRAI DLT / 1600-series
DLT-registered, 1600-series outbound. DND scrub runs before every campaign, not as a report after it.
RBI fair practices
Calling windows and contact frequency enforced by the dialer, not left to the script.
IRDAI conduct
Insurance conversations built to distribution and policyholder-protection conduct requirements.
DPDP Act 2023
Consent capture, data minimisation and purpose limitation built into the flow, with a documented withdrawal path.
A note on wording: we say designed to dpdp act 2023 requirements, not “DPDP certified” or “DPDP compliant”. No certification regime exists under the Act, so no vendor can hold a certificate against it. Anyone claiming one is describing something that does not exist.
Security & data governance
Where the data lives, who can reach it, and what it leaves behind.
Data residency
Recordings, transcripts and metadata on Sovereign infrastructure. Zero-retention mode available for sensitive workflows.
Encryption
In transit and at rest across every layer, from telephony to the grounding corpus.
Auditability
Every call produces an immutable, timestamped record, and every answer traces to its source clause.
Role-based access
Fine-grained permissions so operations, compliance and IT see exactly what they need and nothing more.
Deployment options
Cloud, private cloud and on-premise for institutions whose policy requires it.
Human in the loop
By design, not as a fallback.
Every workflow hands to a human at defined trigger points. No autonomous agent goes into settlement negotiation, hardship determination, or any conversation whose outcome is a legal position.
A compliance breach halts the campaign automatically. It is the one control we do not trade against a revenue target.
Data principal requests
Access, correction, erasure and consent withdrawal.
Consent given on a call or a form can be withdrawn by the same route it was given, and a caller can opt out mid-conversation by saying so.
Send this to your risk team before the first meeting.
The security and compliance overview covers data flows, retention, sub-processors, deployment topologies and the audit record format.
