Live
demo
//security
Security & compliance

Built for the CISOs who have to sign it.

Aelo handles sales conversations — often your most sensitive data. Here's exactly how we protect it.

Encryption

  • TLS 1.2+ in transit
  • AES-256 at rest

Hosting & region

  • Customer content is stored at rest in the EU
  • Cloudflare Workers execute at the edge nearest the request, so processing may occur outside the EU
  • Vendor access, locations and transfer safeguards are listed in our public sub-processor register

PII handling

  • For new transcripts on current write paths, supported phone, email, payment-card and valid IBAN patterns are redacted on write and before model analysis; original audio and earlier rows are unchanged
  • Retention you control: 1 to 365 days, 1 year by default
  • DSR request intake, review and status tracking
  • Approved DSRs use the applicable product or support procedure; execution is not automatic

Access control

  • Four organization roles plus three project roles
  • Organization and project scoping enforced in RBAC
  • API keys bound to one organization, with read and write granted separately
  • Keys stored hashed — the plaintext is shown once, never stored, and revoking one takes effect on the next request

Compliance support

  • Public DPA and sub-processor register
  • Customer-configurable retention: 1 to 365 days
  • DSR request intake, review and status tracking
  • Public privacy policy describing Controller and Processor roles

Sub-processors

  • OpenAI — transcript analysis; ElevenLabs / Deepgram — speech-to-text
  • Cloudflare — hosting, CDN, storage
  • Stripe — payments for our own billing; card details never touch Aelo
  • Full list: sub-processors page
DPA

Data Processing Agreement

Our DPA is published on this site. It covers Controller and Processor roles, technical measures and transfer mechanisms. The public sub-processor register lists each provider, purpose, location and safeguard.

Security questions? security@aelo.cloud