Skip to main content

Trust Center

Last updated: 2026-07-08

Everything procurement, security, and legal teams typically ask about, in one place. We keep this page in sync with what the platform actually does — if you spot a gap or need something not listed, email trust@devotel.io.

Data residency

Production data is processed in the European Union. Primary workload runs in Google Cloud europe-west1 (Belgium) with a Cloud SQL cross-region read replica in europe-west2 (London) for disaster recovery.

Current limitations: we do not yet offer US-only, UK-only, or APAC-only data residency. Customers with a regulatory requirement for region-pinned processing should contact trust@devotel.io so we can scope the work; this is on the roadmap but not GA.

Inbound message and call content may transit a carrier or channel provider before reaching Orbit; each subprocessor's region is listed in the table below.

Subprocessors

Orbit engages the third-party processors listed below to deliver the service. Each is contractually required to protect customer data and use it solely for the services they perform on our behalf. For a standalone page suitable for change-notification subscription, see /subprocessors.

ProcessorPurposeRegionScope
Anthropic · DPALarge-language-model inference for AI agents, classifiers, and Orby in-product assistant.UScontent, metadata
Google Cloud Platform · DPAProduction compute (GKE), managed Postgres (Cloud SQL), object storage (GCS), Secret Manager, Cloud Build, and observability.EU (europe-west1, Belgium) with cross-region replica in europe-west2 (London)account, content, metadata, telemetry
Clerk · DPAUser authentication, session management, multi-factor authentication, and organization membership.USaccount, auth
Stripe · DPAPayment processing, subscription billing, invoice generation, and tax computation. Cardholder data never traverses Orbit systems.US / EU (multi-region)billing
Telnyx · DPAInbound SMS and voice termination on DIDs purchased from Telnyx. Outbound (MT) traffic does NOT flow through Telnyx.US / EU (multi-region)inbound only
DIDWW · DPAInbound voice and SMS termination on DIDs purchased from DIDWW. Outbound (MT) traffic does NOT flow through DIDWW.EU (Latvia)inbound only
Twilio · DPAOne-shot import path only — used at customer request to migrate phone numbers and historical message data into Orbit. No live traffic.USmetadata
Deepgram · DPAReal-time speech-to-text transcription for voice agents and call recordings.UScontent
CartesiaLow-latency text-to-speech synthesis for voice agents.UScontent
ElevenLabs · DPAHigh-quality text-to-speech synthesis for voice agents (alternate provider).UScontent
Devotel Orbit Media · DPASelf-hosted WebRTC media plane (SFU) for live voice agent sessions. Runs inside Devotel’s GCP infrastructure (europe-west1); no audio data leaves Devotel’s own cluster.EU (europe-west1, GCP)content, metadata
PostHog · DPAProduct analytics, session replay (opt-in), and feature-flag evaluation. PII-redaction enabled by default.EU (Frankfurt)telemetry
Sentry · DPAApplication error and performance monitoring. PII scrubbed before transmission.UStelemetry
Resend · DPAOutbound transactional and platform-managed marketing email delivery. Customers are billed at cost plus markup; no BYO SMTP.UScontent, metadata
Meta Platforms (WhatsApp Cloud API) · DPAWhatsApp Business Cloud API for inbound and outbound WhatsApp messaging. Tenants connect their own WABA (BYO).US / globalcontent, metadata
Qdrant Cloud · DPAVector database for retrieval-augmented generation (RAG) over agent knowledge bases. Chunk content encrypted at rest with AES-256-GCM (enc:v1 envelope).EU (Frankfurt)content

SOC 2 control mappings

Below is the mapping of major Trust Services Criteria to Orbit controls. A formal SOC 2 Type II audit is in planning; this table reflects the controls as implemented in the platform today. "Implemented" = control is live in code or infrastructure; "documented, audit pending" = control is operational but awaiting independent attestation.

CriterionDescriptionStatus
CC6.1Logical and physical access controls — Clerk SSO, MFA, per-tenant API keys with rotation.implemented
CC6.2Encryption at rest — AES-256-GCM enc:v1 envelope on PII, OAuth tokens, webhook secrets, RAG chunks.implemented
CC6.3Encryption in transit — TLS 1.2+ on every public endpoint and every internal hop.implemented
CC6.6Vulnerability management — dependency CVE scanning, container image scanning, quarterly review.implemented
CC7.1Detection and monitoring — Sentry error monitoring, PostHog product telemetry, GCP audit logs.implemented
CC7.2Security event identification — automated alerting on auth anomalies, audit-log chain breaks, secret access.documented, audit pending
CC7.3Incident response evaluation — runbooks for provider outages, data exposure, account takeover.documented, audit pending
CC7.4Incident response actions — post-incident review with redacted RCA published within 10 business days.documented, audit pending
CC8.1Change management — pull-request review, pre-submit gate, blue-green Cloud Build deploys.implemented

AI transparency — EU AI Act Article 50

Article 50 of the EU AI Act applies from August 2, 2026 and requires that people are told when they are interacting with an AI system, and that AI-generated audio content is marked as such. Orbit's AI-disclosure controls ship the mechanics an operator needs to meet that obligation today:

  • Automatic "you are speaking with an AI" notice — when enabled, Orbit prepends a configurable chat notice on an AI agent's first reply in a conversation (once per conversation) and plays a configurable voice intro (recorded audio or synthesized text) before an AI voice agent starts speaking on a call.
  • AI-generated content marking — messages sent by an AI agent are stamped with metadata.ai_generated, and recorded calls with AI involvement are stamped with EU AI Act Article 50 provenance metadata on upload. Where the configured text-to-speech provider embeds a perceptually-inaudible watermark (content-credential support varies by provider), that signal is recorded alongside the call.
  • Per-regulation opt-in, not automatic geo-detection — a workspace turns on each regulation that applies to its traffic (EU AI Act §50, Korea's AI Basic Act, California SB 243) under Settings → Compliance → AI Disclosure. Orbit does not infer a contact's jurisdiction from a phone number or address, so an enabled rule applies workspace-wide rather than being switched on or off per contact; the safe default when a rule is off is that its disclosure is never added.
  • Exportable conformity evidence — each AI agent can generate a one-click conformity dossier mapping its transparency configuration, evaluation results, human-oversight approvals, and decision audit log to the relevant EU AI Act articles (12, 14, 15, 50), plus a tamper-evident, cryptographically signed disclosure ledger proving when and where an AI — not a human — handled an interaction.

Disclosure is off by default; a tenant operator opts in per regulation. See the EU AI Act Article 50 documentation for the configuration API and how to export verification evidence.

Documents

For a counter-signed DPA, security questionnaire response (CAIQ, SIG-Lite), penetration-test summary, or any other artifact, please email trust@devotel.io.

Trust Center — Orbit by Devotel